A deserialization vulnerability exists in LangChain4j's AgenticScopeSerializer.fromJson function. This issue affects LangChain4j-agentic and requires an application to have enabled AgenticScope persistence, which is opt-in. An attacker who can already write to that store may exploit this vulnerability remotely with high complexity. The project maintainer has patched all maintained release lines, and upgra [truncated]
LangChain4j, a Java library for building LLM-powered applications, had a vulnerability prior to versions 1.2.1-beta8, 1.5.1-beta11, 1.11.8-beta19, and 1.16.3-beta26. The issue allowed SQL injection attacks through crafted metadata keys in EmbeddingSearchRequest.filter(), enabling data exfiltration, denial of service, and row deletion. This vulnerability was particularly concerning for applications utilizi [truncated]