A critical deserialization vulnerability tracked as CVE-2025-68664 was disclosed in LangChain, affecting the framework's dumps() and dumpd() serialization functions. The flaw stems from improper escaping of dictionaries containing the internal lc key, allowing attacker-controlled input to be interpreted as trusted LangChain objects during deserialization. GitHub's advisory describes the issue as a serialization injection bug that can expose secrets through the dumps/loads APIs, while Red Hat warns the same weakness can lead to remote arbitrary code execution.
Red Hat assigned the issue a CVSS v3 score of 9.3 and classified it as CWE-502 (Deserialization of Untrusted Data), while NVD scored it 8.2. Red Hat said fixes were issued for affected products including Red Hat Ansible Automation Platform 2.4, 2.5, and 2.6, as well as Red Hat OpenShift Lightspeed 1.1.2, through security errata released in January 2026. The vulnerability is also tracked in the official CVE record under CVE-2025-68664.

Track how attackers are adapting to this technology.
4 events from the most recent confirmed update back to the earliest known activity.
Red Hat released security errata RHSA-2026:0406, RHSA-2026:0409, and RHSA-2026:0408 to fix CVE-2025-68664 in Red Hat Ansible Automation Platform 2.4, 2.5, and 2.6. The fixes covered affected Lightspeed-related components in those product streams.
The serialization injection vulnerability in LangChain, tracked as CVE-2025-68664 and GitHub advisory GHSA-c67j-w6g6-q2cm, was publicly disclosed. The issue affects dumps() and dumpd() handling of dictionaries containing the internal 'lc' key, enabling attacker-controlled deserialization behavior.
Red Hat released RHSA-2026:1610 to address CVE-2025-68664 in Red Hat OpenShift Lightspeed 1.1.2. The fixed component listed was openshift-lightspeed/lightspeed-service-api-rhel9.
Upstream fixes were issued for the vulnerability in patched releases langchain-core 0.3.81 and 1.2.5, with Red Hat also referencing upstream commits and pull requests tied to the remediation. The content does not explicitly anchor a release date for these upstream patches.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourcegithub.com
Open sourcecve.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.