Skip to content

bump langchain#1929

Merged
petrkalos merged 1 commit intomainfrom
fix/bump_langchain
Mar 18, 2026
Merged

bump langchain#1929
petrkalos merged 1 commit intomainfrom
fix/bump_langchain

Conversation

@petrkalos
Copy link
Copy Markdown
Contributor

-> Vulnerability found in langchain-core version 1.2.5
Vulnerability ID: 86270
Affected spec: <1.2.11
ADVISORY: Affected versions of the langchain-core package are
vulnerable to Server-Side Request Forgery (SSRF) due to fetching user-...
CVE-2026-26013
For more information about this vulnerability, visit
https://data.safetycli.com/v/86270/97c
To ignore this vulnerability, use PyUp vulnerability id 86270 in safety’s
ignore command-line argument or add the ignore to your safety policy file.

@petrkalos petrkalos merged commit 646275e into main Mar 18, 2026
13 checks passed
@petrkalos petrkalos deleted the fix/bump_langchain branch March 18, 2026 15:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant