Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.Packages you depend on that have known security holes (CVEs).
CVE-2023-34540 Langchain OS Command Injection vulnerabilityCVE-2023-34541 Langchain vulnerable to arbitrary code executionCVE-2023-36095 langchain Code Injection vulnerabilityCVE-2023-36188 langchain vulnerable to arbitrary code executionCVE-2023-36258 langchain arbitrary code execution vulnerabilityCVE-2023-36281 langchain vulnerable to arbitrary code executionCVE-2023-38860 LangChain vulnerable to arbitrary code executionCVE-2023-38896 LangChain vulnerable to arbitrary code executionCVE-2023-39631 Langchain vulnerable to arbitrary code execution via the evaluate function in the numexpr libraryCVE-2023-39659 LangChain vulnerable to arbitrary code executionCVE-2023-45133 babel: arbitrary code executionCVE-2025-7783 form-data: Unsafe random function in form-dataCVE-2026-48713 i18next-fs-backend vulnerable to prototype pollution via crafted missing-key stringCVE-2025-29927 nextjs: Authorization Bypass in Next.js MiddlewareCVE-2024-6221 A vulnerability in corydolphin/flask-cors version 4.0.1 allows the `Ac ...CVE-2024-1681 corydolphin/flask-cors is vulnerable to log injection when the log lev ...CVE-2024-6839 corydolphin/flask-cors version 4.0.1 contains an improper regex path m ...CVE-2024-6844 A vulnerability in corydolphin/flask-cors version 4.0.1 allows for inc ...CVE-2024-6866 corydolphin/flask-cors version 4.01 contains a vulnerability where the ...CVE-2023-32786 Langchain Server-Side Request Forgery vulnerabilityCVE-2023-36189 langchain SQL Injection vulnerabilityCVE-2023-46229 langchain: langchain SSRFCVE-2026-45134 LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warningCVE-2024-2965 langchain-community: Langchain-community SitemapParser DoS VulnerabilityCVE-2024-3571 langchain vulnerable to path traversalYour dependencies cross-checked against the OSV vulnerability database.
PYSEC-2023-109 An issue in langchain v.0.0.64 allows a remote attacker to execute arbitrary code via the PALChain parameter in the Python exec method.PYSEC-2023-138 An issue in Harrison Chase langchain v.0.0.194 allows an attacker to execute arbitrary code via the python exec calls in the PALChain, affected functions include from_math_prompt and from_colored_objePYSEC-2023-145 An issue in LangChain v.0.0.231 allows a remote attacker to execute arbitrary code via the prompt parameter.PYSEC-2023-146 An issue in Harrison Chase langchain v.0.0.194 and before allows a remote attacker to execute arbitrary code via the from_math_prompt and from_colored_object_prompt functions.PYSEC-2023-147 An issue in langchain langchain-ai v.0.0.232 and before allows a remote attacker to execute arbitrary code via a crafted script to the PythonAstREPLTool._run component.PYSEC-2023-162 An issue in LanChain-ai Langchain v.0.0.245 allows a remote attacker to execute arbitrary code via the evaluate function in the numexpr library.PYSEC-2023-91 Langchain 0.0.171 is vulnerable to Arbitrary Code Execution.PYSEC-2023-92 Langchain 0.0.171 is vulnerable to Arbitrary code execution in load_prompt.PYSEC-2023-98 An issue in langchain v.0.0.199 allows an attacker to execute arbitrary code via the PALChain in the python exec method.PYSEC-2026-372 Langchain SQL Injection vulnerabilityGHSA-7gfq-f96f-g85j langchain vulnerable to arbitrary code executionGHSA-67hx-6x53-jw92 Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious codeGHSA-gx9m-whjm-85jf DOMpurify has a nesting-based mXSSGHSA-fjxv-7rqg-78g4 form-data uses unsafe random function in form-data for choosing boundaryGHSA-2933-q333-qg83 i18next-fs-backend vulnerable to prototype pollution via crafted missing-key stringGHSA-f82v-jwr5-mffw Authorization Bypass in Next.js MiddlewareGHSA-5xrq-8626-4rwp When Vitest UI server is listening, arbitrary file can be read and executedPYSEC-2026-2151 Flask is a web server gateway interface (WSGI) web application framework. In versions 3.1.2 and below, when the session object is accessed, Flask should set the Vary: Cookie header., resulting in a UsPYSEC-2023-110 SQL injection vulnerability in langchain v.0.0.64 allows a remote attacker to obtain sensitive information via the SQLDatabaseChain component.PYSEC-2023-205 LangChain before 0.0.317 allows SSRF via document_loaders/recursive_url_loader.py because crawling can proceed from an external server to an internal server.PYSEC-2024-118 A Denial-of-Service (DoS) vulnerability exists in the `SitemapLoader` class of the `langchain-ai/langchain` repository, affecting all versions. The `parse_sitemap` method, responsible for parsing sitePYSEC-2024-323 A vulnerability in the FAISS.deserialize_from_bytes function of langchain-ai/langchain allows for pickle deserialization of untrusted data. This can lead to the execution of arbitrary commands via thePYSEC-2026-1507 Langchain SQL Injection vulnerabilityPYSEC-2026-1508 Langchain Server-Side Request Forgery vulnerabilityPYSEC-2026-1510 langchain vulnerable to path traversalCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
scorecard-overall OpenSSF Scorecard overall: 4.5/10scorecard-CI-Tests CI-Tests scored 0: 0 out of 21 merged PRs checked by a CI test -- score normalized to 0scorecard-CII-Best-Practices CII-Best-Practices scored 0: no effort to earn an OpenSSF best practices badge detectedscorecard-Dependency-Update-Tool Dependency-Update-Tool scored 0: no update tool detectedscorecard-Fuzzing Fuzzing scored 0: project is not fuzzedscorecard-Maintained Maintained scored 0: 0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0scorecard-Pinned-Dependencies Pinned-Dependencies scored 0: dependency not pinned by hash detected -- score normalized to 0scorecard-SAST SAST scored 0: SAST tool is not run on all commits -- score normalized to 0scorecard-Security-Policy Security-Policy scored 0: security policy file not detected