gitsafehub
github.com/xlang-ai/openagents ↗

xlang-ai/openagents

scanned 2026-07-15 · git ff2e464
3 of 6 checks flagged a security issue
🔴 Needs attention
6 checks ran. Start with known oss vulnerabilities below.

Informational scan, not a security audit. How this is computed.

Leaked secrets2Vulnerable dependencies146Known OSS vulnerabilities178Risky code patternsMalicious dependenciesProject health9

Security checks

Leaked secrets — Gitleaks 2 found

API keys, passwords or tokens committed into the repo.

  • Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    real_agents/plugins_agent/plugins/property_search/ai-plugin.json:19
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    real_agents/plugins_agent/plugins/zapier/ai-plugin.json:31
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.

via Gitleaks v8.21.2 · MIT

Vulnerable dependencies — Trivy 146 found · 14 serious

Packages you depend on that have known security holes (CVEs).

  • Serious CVE-2023-34540 Langchain OS Command Injection vulnerability
    backend/requirements.txt
    A package you depend on has a known security hole (CVE-2023-34540). Fix: Update that package to its patched version.
  • Serious CVE-2023-34541 Langchain vulnerable to arbitrary code execution
    backend/requirements.txt
    A package you depend on has a known security hole (CVE-2023-34541). Fix: Update that package to its patched version.
  • Serious CVE-2023-36095 langchain Code Injection vulnerability
    backend/requirements.txt
    A package you depend on has a known security hole (CVE-2023-36095). Fix: Update that package to its patched version.
  • Serious CVE-2023-36188 langchain vulnerable to arbitrary code execution
    backend/requirements.txt
    A package you depend on has a known security hole (CVE-2023-36188). Fix: Update that package to its patched version.
  • Serious CVE-2023-36258 langchain arbitrary code execution vulnerability
    backend/requirements.txt
    A package you depend on has a known security hole (CVE-2023-36258). Fix: Update that package to its patched version.
  • Serious CVE-2023-36281 langchain vulnerable to arbitrary code execution
    backend/requirements.txt
    A package you depend on has a known security hole (CVE-2023-36281). Fix: Update that package to its patched version.
  • Serious CVE-2023-38860 LangChain vulnerable to arbitrary code execution
    backend/requirements.txt
    A package you depend on has a known security hole (CVE-2023-38860). Fix: Update that package to its patched version.
  • Serious CVE-2023-38896 LangChain vulnerable to arbitrary code execution
    backend/requirements.txt
    A package you depend on has a known security hole (CVE-2023-38896). Fix: Update that package to its patched version.
  • Serious CVE-2023-39631 Langchain vulnerable to arbitrary code execution via the evaluate function in the numexpr library
    backend/requirements.txt
    A package you depend on has a known security hole (CVE-2023-39631). Fix: Update that package to its patched version.
  • Serious CVE-2023-39659 LangChain vulnerable to arbitrary code execution
    backend/requirements.txt
    A package you depend on has a known security hole (CVE-2023-39659). Fix: Update that package to its patched version.
  • Serious CVE-2023-45133 babel: arbitrary code execution
    frontend/package-lock.json
    A package you depend on has a known security hole (CVE-2023-45133). Fix: Update that package to its patched version.
  • Serious CVE-2025-7783 form-data: Unsafe random function in form-data
    frontend/package-lock.json
    A package you depend on has a known security hole (CVE-2025-7783). Fix: Update that package to its patched version.
  • Serious CVE-2026-48713 i18next-fs-backend vulnerable to prototype pollution via crafted missing-key string
    frontend/package-lock.json
    A package you depend on has a known security hole (CVE-2026-48713). Fix: Update that package to its patched version.
  • Serious CVE-2025-29927 nextjs: Authorization Bypass in Next.js Middleware
    frontend/package-lock.json
    A package you depend on has a known security hole (CVE-2025-29927). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-6221 A vulnerability in corydolphin/flask-cors version 4.0.1 allows the `Ac ...
    backend/requirements.txt
    A package you depend on has a known security hole (CVE-2024-6221). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-1681 corydolphin/flask-cors is vulnerable to log injection when the log lev ...
    backend/requirements.txt
    A package you depend on has a known security hole (CVE-2024-1681). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-6839 corydolphin/flask-cors version 4.0.1 contains an improper regex path m ...
    backend/requirements.txt
    A package you depend on has a known security hole (CVE-2024-6839). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-6844 A vulnerability in corydolphin/flask-cors version 4.0.1 allows for inc ...
    backend/requirements.txt
    A package you depend on has a known security hole (CVE-2024-6844). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-6866 corydolphin/flask-cors version 4.01 contains a vulnerability where the ...
    backend/requirements.txt
    A package you depend on has a known security hole (CVE-2024-6866). Fix: Update that package to its patched version.
  • Worth fixing CVE-2023-32786 Langchain Server-Side Request Forgery vulnerability
    backend/requirements.txt
    A package you depend on has a known security hole (CVE-2023-32786). Fix: Update that package to its patched version.
  • Worth fixing CVE-2023-36189 langchain SQL Injection vulnerability
    backend/requirements.txt
    A package you depend on has a known security hole (CVE-2023-36189). Fix: Update that package to its patched version.
  • Worth fixing CVE-2023-46229 langchain: langchain SSRF
    backend/requirements.txt
    A package you depend on has a known security hole (CVE-2023-46229). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-45134 LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning
    backend/requirements.txt
    A package you depend on has a known security hole (CVE-2026-45134). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-2965 langchain-community: Langchain-community SitemapParser DoS Vulnerability
    backend/requirements.txt
    A package you depend on has a known security hole (CVE-2024-2965). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-3571 langchain vulnerable to path traversal
    backend/requirements.txt
    A package you depend on has a known security hole (CVE-2024-3571). Fix: Update that package to its patched version.
… 121 more not shown

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner 178 found · 17 serious

Your dependencies cross-checked against the OSV vulnerability database.

  • Serious PYSEC-2023-109 An issue in langchain v.0.0.64 allows a remote attacker to execute arbitrary code via the PALChain parameter in the Python exec method.
    /workdirs/scan-ae8f79f8-0114-4ba7-b9fe-580324120370/backend/requirements.txt
    A package you depend on has a known security hole (CVE-2023-36188). Fix: Update that package to its patched version.
  • Serious PYSEC-2023-138 An issue in Harrison Chase langchain v.0.0.194 allows an attacker to execute arbitrary code via the python exec calls in the PALChain, affected functions include from_math_prompt and from_colored_obje
    /workdirs/scan-ae8f79f8-0114-4ba7-b9fe-580324120370/backend/requirements.txt
    A package you depend on has a known security hole (CVE-2023-36095). Fix: Update that package to its patched version.
  • Serious PYSEC-2023-145 An issue in LangChain v.0.0.231 allows a remote attacker to execute arbitrary code via the prompt parameter.
    /workdirs/scan-ae8f79f8-0114-4ba7-b9fe-580324120370/backend/requirements.txt
    A package you depend on has a known security hole (CVE-2023-38860). Fix: Update that package to its patched version.
  • Serious PYSEC-2023-146 An issue in Harrison Chase langchain v.0.0.194 and before allows a remote attacker to execute arbitrary code via the from_math_prompt and from_colored_object_prompt functions.
    /workdirs/scan-ae8f79f8-0114-4ba7-b9fe-580324120370/backend/requirements.txt
    A package you depend on has a known security hole (CVE-2023-38896). Fix: Update that package to its patched version.
  • Serious PYSEC-2023-147 An issue in langchain langchain-ai v.0.0.232 and before allows a remote attacker to execute arbitrary code via a crafted script to the PythonAstREPLTool._run component.
    /workdirs/scan-ae8f79f8-0114-4ba7-b9fe-580324120370/backend/requirements.txt
    A package you depend on has a known security hole (CVE-2023-39659). Fix: Update that package to its patched version.
  • Serious PYSEC-2023-162 An issue in LanChain-ai Langchain v.0.0.245 allows a remote attacker to execute arbitrary code via the evaluate function in the numexpr library.
    /workdirs/scan-ae8f79f8-0114-4ba7-b9fe-580324120370/backend/requirements.txt
    A package you depend on has a known security hole (CVE-2023-39631). Fix: Update that package to its patched version.
  • Serious PYSEC-2023-91 Langchain 0.0.171 is vulnerable to Arbitrary Code Execution.
    /workdirs/scan-ae8f79f8-0114-4ba7-b9fe-580324120370/backend/requirements.txt
    A package you depend on has a known security hole (CVE-2023-34540). Fix: Update that package to its patched version.
  • Serious PYSEC-2023-92 Langchain 0.0.171 is vulnerable to Arbitrary code execution in load_prompt.
    /workdirs/scan-ae8f79f8-0114-4ba7-b9fe-580324120370/backend/requirements.txt
    A package you depend on has a known security hole (CVE-2023-34541). Fix: Update that package to its patched version.
  • Serious PYSEC-2023-98 An issue in langchain v.0.0.199 allows an attacker to execute arbitrary code via the PALChain in the python exec method.
    /workdirs/scan-ae8f79f8-0114-4ba7-b9fe-580324120370/backend/requirements.txt
    A package you depend on has a known security hole (CVE-2023-36258). Fix: Update that package to its patched version.
  • Serious PYSEC-2026-372 Langchain SQL Injection vulnerability
    /workdirs/scan-ae8f79f8-0114-4ba7-b9fe-580324120370/backend/requirements.txt
    A package you depend on has a known security hole (CVE-2023-32785). Fix: Update that package to its patched version.
  • Serious GHSA-7gfq-f96f-g85j langchain vulnerable to arbitrary code execution
    /workdirs/scan-ae8f79f8-0114-4ba7-b9fe-580324120370/backend/requirements.txt
    A package you depend on has a known security hole (CVE-2023-36281). Fix: Update that package to its patched version.
  • Serious GHSA-67hx-6x53-jw92 Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious code
    /workdirs/scan-ae8f79f8-0114-4ba7-b9fe-580324120370/frontend/package-lock.json
    A package you depend on has a known security hole (CVE-2023-45133). Fix: Update that package to its patched version.
  • Serious GHSA-gx9m-whjm-85jf DOMpurify has a nesting-based mXSS
    /workdirs/scan-ae8f79f8-0114-4ba7-b9fe-580324120370/frontend/package-lock.json
    A package you depend on has a known security hole (CVE-2024-47875). Fix: Update that package to its patched version.
  • Serious GHSA-fjxv-7rqg-78g4 form-data uses unsafe random function in form-data for choosing boundary
    /workdirs/scan-ae8f79f8-0114-4ba7-b9fe-580324120370/frontend/package-lock.json
    A package you depend on has a known security hole (CVE-2025-7783). Fix: Update that package to its patched version.
  • Serious GHSA-2933-q333-qg83 i18next-fs-backend vulnerable to prototype pollution via crafted missing-key string
    /workdirs/scan-ae8f79f8-0114-4ba7-b9fe-580324120370/frontend/package-lock.json
    A package you depend on has a known security hole (CVE-2026-48713). Fix: Update that package to its patched version.
  • Serious GHSA-f82v-jwr5-mffw Authorization Bypass in Next.js Middleware
    /workdirs/scan-ae8f79f8-0114-4ba7-b9fe-580324120370/frontend/package-lock.json
    A package you depend on has a known security hole (CVE-2025-29927). Fix: Update that package to its patched version.
  • Serious GHSA-5xrq-8626-4rwp When Vitest UI server is listening, arbitrary file can be read and executed
    /workdirs/scan-ae8f79f8-0114-4ba7-b9fe-580324120370/frontend/package-lock.json
    A package you depend on has a known security hole (CVE-2026-47429). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2151 Flask is a web server gateway interface (WSGI) web application framework. In versions 3.1.2 and below, when the session object is accessed, Flask should set the Vary: Cookie header., resulting in a Us
    /workdirs/scan-ae8f79f8-0114-4ba7-b9fe-580324120370/backend/requirements.txt
    A package you depend on has a known security hole (CVE-2026-27205). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2023-110 SQL injection vulnerability in langchain v.0.0.64 allows a remote attacker to obtain sensitive information via the SQLDatabaseChain component.
    /workdirs/scan-ae8f79f8-0114-4ba7-b9fe-580324120370/backend/requirements.txt
    A package you depend on has a known security hole (CVE-2023-36189). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2023-205 LangChain before 0.0.317 allows SSRF via document_loaders/recursive_url_loader.py because crawling can proceed from an external server to an internal server.
    /workdirs/scan-ae8f79f8-0114-4ba7-b9fe-580324120370/backend/requirements.txt
    A package you depend on has a known security hole (CVE-2023-46229). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2024-118 A Denial-of-Service (DoS) vulnerability exists in the `SitemapLoader` class of the `langchain-ai/langchain` repository, affecting all versions. The `parse_sitemap` method, responsible for parsing site
    /workdirs/scan-ae8f79f8-0114-4ba7-b9fe-580324120370/backend/requirements.txt
    A package you depend on has a known security hole (CVE-2024-2965). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2024-323 A vulnerability in the FAISS.deserialize_from_bytes function of langchain-ai/langchain allows for pickle deserialization of untrusted data. This can lead to the execution of arbitrary commands via the
    /workdirs/scan-ae8f79f8-0114-4ba7-b9fe-580324120370/backend/requirements.txt
    A package you depend on has a known security hole (CVE-2024-5998). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1507 Langchain SQL Injection vulnerability
    /workdirs/scan-ae8f79f8-0114-4ba7-b9fe-580324120370/backend/requirements.txt
    A package you depend on has a known security hole (CVE-2024-8309). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1508 Langchain Server-Side Request Forgery vulnerability
    /workdirs/scan-ae8f79f8-0114-4ba7-b9fe-580324120370/backend/requirements.txt
    A package you depend on has a known security hole (CVE-2023-32786). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1510 langchain vulnerable to path traversal
    /workdirs/scan-ae8f79f8-0114-4ba7-b9fe-580324120370/backend/requirements.txt
    A package you depend on has a known security hole (CVE-2024-3571). Fix: Update that package to its patched version.
… 153 more not shown

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog none found ✓

Packages that look intentionally malicious: typosquats, sneaky install scripts.

Nothing found by this check. ✓

via Guarddog v2.10.0 · Apache-2.0

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard 9 notes

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

  • Minor scorecard-overall OpenSSF Scorecard overall: 4.5/10
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-CI-Tests CI-Tests scored 0: 0 out of 21 merged PRs checked by a CI test -- score normalized to 0
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-CII-Best-Practices CII-Best-Practices scored 0: no effort to earn an OpenSSF best practices badge detected
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-Dependency-Update-Tool Dependency-Update-Tool scored 0: no update tool detected
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-Fuzzing Fuzzing scored 0: project is not fuzzed
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-Maintained Maintained scored 0: 0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-Pinned-Dependencies Pinned-Dependencies scored 0: dependency not pinned by hash detected -- score normalized to 0
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-SAST SAST scored 0: SAST tool is not run on all commits -- score normalized to 0
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-Security-Policy Security-Policy scored 0: security policy file not detected
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.

via OpenSSF Scorecard v5.5.0 · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.