langchain-nvidia-ai-endpoints is vulnerable to Information Disclosure
40
Medium Risk
Affected versions of the langchain-nvidia-ai-endpoints library expose an unredacted API key in the NVIDIAClient output, which is used by wrappers such as ChatNVIDIA. This key could end up in logs or other sources depending on how the library is used.
You are affected if you use a vulnerable version of langchain-nvidia-ai-endpoints.
langchain-nvidia-ai-endpoints is vulnerable to Information Disclosure in versions 0.0.1 - 0.1.1.
Upgrade langchain-nvidia-ai-endpoints to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant