CVE-2024-3571: medium-severity vulnerability in langchain-ai/langchain
Path Traversal in langchain-ai/langchain
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.5epss 1.9%
exploitation probability
1.9%top 21% of all CVEs
observed exploitation
nono source reports it
langchain-ai/langchain is vulnerable to path traversal due to improper limitation of a pathname to a restricted directory ('Path Traversal') in its LocalFileStore functionality. An attacker can leverage this vulnerability to read or write files anywhere on the filesystem, potentially leading to information disclosure or remote code execution. The issue lies in the handling of file paths in the mset and mget methods, where user-supplied input is not adequately sanitized, allowing directory traversal sequences to reach unintended directories.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected products
langchain-ai · langchain-ai/langchainRelated CVEs — langchain-ai/langchain
In the same product, most dangerous first.
CVE-2025-2828HIGHSSRF Vulnerability in RequestsToolkit in langchain-ai/langchainEPSS 21.0%CVE-2024-8309MEDIUMSQL Injection in langchain-ai/langchainEPSS 13.7%CVE-2025-6984HIGHSensitive Information Disclosure Due to Insecure XML Parsing in langchain-ai/langchainEPSS 1.6%CVE-2024-1455MEDIUMBillion Laughs Attack leading to DoS in langchain-ai/langchainEPSS 0.8%CVE-2024-3095MEDIUMSSRF in Langchain Web Research Retriever in langchain-ai/langchainEPSS 0.7%CVE-2024-0243LOWServer-side Request Forgery In Recursive URL LoaderEPSS 0.5%