{"id":"CVE-2024-7774","aliases":["GHSA-hc5w-c9f8-9cc4"],"url":"https://o3.security/vulnerability/CVE-2024-7774","summary":"Path Traversal in langchain-ai/langchainjs","details":"A path traversal vulnerability exists in the `getFullPath` method of langchain-ai/langchainjs version 0.2.5. This vulnerability allows attackers to save files anywhere in the filesystem, overwrite existing text files, read `.txt` files, and delete files. The vulnerability is exploited through the `setFileContent`, `getParsedFile`, and `mdelete` methods, which do not properly sanitize user input.","published":"2024-10-29T12:49:21.165Z","modified":"2026-08-12T03:51:42.515286296Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"},"epss":{"score":0.00552,"percentile":0.44827,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"npm","name":"langchain","fixedVersion":"0.2.19"}],"fix":{"url":"https://github.com/langchain-ai/langchainjs/commit/a0fad77d6b569e5872bd4a9d33be0c0785e538a9","label":"langchain-ai/langchainjs@a0fad77"},"references":[{"type":"WEB","url":"https://huntr.com/bounties/8fe40685-b714-4191-af7a-3de5e5628cee"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/7xxx/CVE-2024-7774.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-7774"},{"type":"FIX","url":"https://github.com/langchain-ai/langchainjs/commit/a0fad77d6b569e5872bd4a9d33be0c0785e538a9"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:42.515286296Z"}}