Intel

AIKIDO-2025-10164

langchain is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

Exposure of Sensitive Information to an Unauthorized Actor Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Mar 18, 2025

25

Low Risk

This Affects:

ELIXIRlangchain
0.1.1 - 0.3.1
Fixed in 0.3.2
Are you affected? Scan for Free

TL;DR

Affected versions of this package may expose sensitive information. When inspecting certain models that contain API keys, the data may be inadvertently logged, leading to potential exposure of sensitive credentials.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

langchain is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 0.1.1 - 0.3.1.

How to fix this

Upgrade the langchain library to the patch version.