Two critical serialization injection vulnerabilities were discovered in the LangChain framework, which is widely used for building LLM-powered applications. The first vulnerability (CVE-2025-68665) affects the toJSON() method in LangChain JS and related serialization routines, where user-controlled data containing the reserved lc key could be misinterpreted as legitimate LangChain objects during deserialization. The second vulnerability (CVE-2025-68664) impacts the dumps() and dumpd() functions, allowing attacker-supplied dictionaries with the lc key to be treated as internal objects, potentially leading to the extraction of secrets or the instantiation of internal classes with attacker-defined parameters. Both vulnerabilities are remotely exploitable and have been patched in recent versions of LangChain and LangChain Core.
Exploitation of these flaws could allow attackers to extract sensitive information such as environment variables or manipulate application behavior by injecting malicious data structures. Organizations using affected versions of LangChain are strongly advised to upgrade to the patched releases—@langchain/core versions 0.3.80 and 1.1.8, langchain versions 0.3.37 and 1.2.3 for CVE-2025-68665, and langchain-core 0.3.81 and 1.2.5 for CVE-2025-68664—to mitigate the risk of exploitation.

Track how attackers are adapting to this technology.
5 events from the most recent confirmed update back to the earliest known activity.
Public write-ups described how prompt-injected or otherwise user-controlled dictionaries containing the reserved 'lc' key could trigger unsafe deserialization, secret extraction, and potentially SSRF, file operations, or code execution. The reporting also attributed the discovery of CVE-2025-68664 to a Cyata researcher and highlighted broad exposure in AI application workflows.
On December 23, 2025, the two LangChain serialization injection vulnerabilities were published in advisories and vulnerability feeds. Public disclosure identified CVE-2025-68664 as a critical LangChain Core issue and CVE-2025-68665 as a high-severity LangChain JS issue.
A related serialization injection issue in LangChain JS, tracked as CVE-2025-68665, was fixed in @langchain/core 0.3.80 and 1.1.8 and langchain 0.3.37 and 1.2.3. The flaw in the toJSON() path could let attacker-controlled data be deserialized as legitimate LangChain objects and expose secrets.
LangChain released fixes for CVE-2025-68664 in langchain-core 0.3.81 and 1.2.5. The patch escaped reserved keys, restricted unsafe object reconstruction, and disabled secret resolution by default.
A critical serialization injection vulnerability later tracked as CVE-2025-68664 was reported to LangChain in early December 2025. The flaw affected LangChain Core's handling of user-controlled data during serialization and deserialization.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
6 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcethehackernews.com
Open sourcecyata.ai
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceupwind.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.