Core LangChain.js abstractions and schemas
93%
Total Score
67
100
100
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2025-68665 @langchain/core is vulnerable to Deserialization of Untrusted Data in versions 1.0.0 - 1.1.8 and 0.0.0 - 0.3.80. | 0.0.0 - 0.3.801.0.0 - 1.1.8 | High |
AIKIDO-2025-10389 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @langchain/core is vulnerable to Use of Weak Hash in versions 0.0.0 - 0.3.59. | 0.0.0 - 0.3.59 | Low |
| Dependency | Last Release | Score |
|---|---|---|
zod Version ^3.25.76 || ^4 | — | — |
p-queue Version ^6.6.2 | — | — |
mustache Version ^4.2.0 | — | — |
langsmith Version >=0.5.0 <1.0.0 | — | — |
js-tiktoken Version ^1.0.12 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant