LangChain prompt-template validation flaw and LangChain-ChatChat MCP RCE disclosed
Two vulnerabilities were disclosed in the LangChain ecosystem: incomplete f-string prompt-template validation in LangChain (CVE-2026-40087) allowed attribute-access and nested replacement-field expressions to be evaluated during formatting, fixed in langchain-core 0.3.84 and 1.2.28; and LangChain-ChatChat 0.3.1 (CVE-2026-30617) allowed a remote attacker to configure an MCP STDIO server via an exposed management interface and execute arbitrary commands when agents run.
Disclosed 9 April 2026 · Record updated 13 September 2026
Impact
Unsafe evaluation of expressions in prompt templates in LangChain prior to 0.3.84/1.2.28, and arbitrary command execution within the context of the LangChain-ChatChat 0.3.1 service via attacker-configured MCP STDIO servers.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-40087
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-30617
