📡 GitHub-Advisory · 2026-05-08
CVE-2026-44843 - LangChain vulnerable to unsafe deserialization of attacker-controlled objects th
CVE-2026-44843
GHSA-pjwx-r37v-7724 HIGH pip/langchain-core
CVE: CVE-2026-44843
LangChain contains older runtime code paths that deserialize run inputs, run outputs, or other application-controlled payloads using overly broad object allowlists. These paths may call load() with allowed_objects="