CVE-2025-65106
HIGHlangchain-core 1.0.0-1.0.6 - Template Injection via Untrusted Template Strings
Title source: llmDescription
LangChain is a framework for building agents and LLM-powered applications. From versions 0.3.79 and prior and 1.0.0 to 1.0.6, a template injection vulnerability exists in LangChain's prompt template system that allows attackers to access Python object internals through template syntax. This vulnerability affects applications that accept untrusted template strings (not just template variables) in ChatPromptTemplate and related prompt template classes. This issue has been patched in versions 0.3.80 and 1.0.7.
References (3)
Core 3
Core References
Vendor Advisory x_refsource_confirm
https://github.com/langchain-ai/langchain/security/advisories/GHSA-6qv9-48xg-fc7f
Patch x_refsource_misc
https://github.com/langchain-ai/langchain/commit/c4b6ba254e1a49ed91f2e268e6484011c540542a
Scores
CVSS v4
8.3
EPSS
0.0045
EPSS Percentile
35.5%
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-1336
Status
published
Products (3)
langchain-ai/langchain
< 0.3.80
langchain-ai/langchain
>= 1.0.0, < 1.0.7
pypi/langchain-core
1.0.0 - 1.0.7PyPI
Published
Nov 21, 2025
Tracked Since
Feb 18, 2026