Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CVE-2026-55443: LangChain path traversal allows file disclosure outside intended root

Several LangChain components that resolve filesystem paths or expand search patterns failed to confine resolved paths to the intended root directory, so glob patterns, symlinks and prefix-based authorization checks could expose files outside the configured boundary when path values or workspace contents were influenced by untrusted input, including an LLM. Fixed in LangChain 1.3.9.

Disclosed 22 June 2026 · Record updated 13 September 2026

Impact

Disclosure of files outside the intended root directory in agents and applications built with affected LangChain components.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-55443