6 comments

  • prodigycorp 17 minutes ago

    The best part about this is that you know the type of people/companies using langchain are likely the type that are not going to patch this in a timely manner.

      wilkystyle 9 minutes ago

      Can you elaborate? Fairly new to langchain, but didn't realize it had any sort of stereotypical type of user.

  • nubg an hour ago

    WHY on earth did the author of the CVE feel the need to feed the description text through an LLm? I get dizzy when I see this AI slop style.

    I would rather just read the original prompt that went in instead of verbosified "it's not X, it's **Y**!" slop.

      iamacyborg 41 minutes ago

      > WHY on earth did the author of the CVE feel the need to feed the description text through an LLm?

      Not everyone speaks English natively.

      Not everyone has taste when it comes to written English.

        nubg 39 minutes ago

        If I want to cleanup, summarize, translate, make more formal, make more funny, whatever, some incoming text by sending it through an LLM, I can do it myself.

  • shahartal 3 hours ago

    CVE-2025-68664 (langchain-core): object confusion during (de)serialization can leak secrets (and in some cases escalate further). Details and mitigations in the post.