{"id":"CVE-2024-28088","aliases":["GHSA-h59x-p739-982c","PYSEC-2024-43","PYSEC-2024-45"],"url":"https://o3.security/vulnerability/CVE-2024-28088","summary":"LangChain directory traversal vulnerability","details":"LangChain through 0.1.10 allows ../ directory traversal by an actor who is able to control the final part of the path parameter in a load_chain call. This bypasses the intended behavior of loading configurations only from the hwchase17/langchain-hub GitHub repository. The outcome can be disclosure of an API key for a large language model online service, or remote code execution. (A patch is available as of release 0.1.29 of langchain-core.)","published":"2024-03-03T00:00:00Z","modified":"2026-08-12T03:51:33.536273278Z","cvss":{"score":8.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"},"epss":{"score":0.0174,"percentile":0.76625,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":2,"affectedPackages":[{"ecosystem":"PyPI","name":"langchain","fixedVersion":"0.0.339"},{"ecosystem":"PyPI","name":"langchain-core","fixedVersion":"0.1.30"}],"fix":{"url":"https://github.com/langchain-ai/langchain/pull/18600","label":"langchain-ai/langchain#18600"},"references":[{"type":"WEB","url":"https://github.com/PinkDraconian/PoC-Langchain-RCE/blob/main/README.md"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/blob/f96dd57501131840b713ed7c2e86cbf1ddc2761f/libs/core/langchain_core/utils/loading.py"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/28xxx/CVE-2024-28088.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-28088"},{"type":"FIX","url":"https://github.com/langchain-ai/langchain/pull/18600"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/e1924b3e93d513ca950c72f8e80e1c133749fba5"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/langchain-core/PYSEC-2024-45.yaml"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/langchain/PYSEC-2024-43.yaml"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:33.536273278Z"}}