PatchSiren

LangChain4j CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW LangChain4j CVE published 2026-09-25

CVE-2026-97869

A deserialization vulnerability exists in LangChain4j's AgenticScopeSerializer.fromJson function. This issue affects LangChain4j-agentic and requires an application to have enabled AgenticScope persistence, which is opt-in. An attacker who can already write to that store may exploit this vulnerability remotely with high complexity. The project maintainer has patched all maintained release lines, and upgra [truncated]

HIGH langchain4j CVE published 2026-07-10

CVE-2026-55405

LangChain4j, a Java library for building LLM-powered applications, had a vulnerability prior to versions 1.2.1-beta8, 1.5.1-beta11, 1.11.8-beta19, and 1.16.3-beta26. The issue allowed SQL injection attacks through crafted metadata keys in EmbeddingSearchRequest.filter(), enabling data exfiltration, denial of service, and row deletion. This vulnerability was particularly concerning for applications utilizi [truncated]