chore(deps): update dependency langchain-core to v0.3.15 [security] - #85
Merged
loeng2023 merged 1 commit intoJul 1, 2025
Conversation
|
/gcbrun |
renovate-bot
force-pushed
the
renovate/pypi-langchain-core-vulnerability
branch
from
May 28, 2025 09:40
96829b0 to
2feb378
Compare
|
/gcbrun |
renovate-bot
force-pushed
the
renovate/pypi-langchain-core-vulnerability
branch
from
May 28, 2025 23:04
2feb378 to
2d24bf2
Compare
|
/gcbrun |
renovate-bot
force-pushed
the
renovate/pypi-langchain-core-vulnerability
branch
from
May 29, 2025 05:29
2d24bf2 to
94f1d72
Compare
|
/gcbrun |
renovate-bot
force-pushed
the
renovate/pypi-langchain-core-vulnerability
branch
from
May 29, 2025 14:02
94f1d72 to
8f97bcb
Compare
|
/gcbrun |
renovate-bot
force-pushed
the
renovate/pypi-langchain-core-vulnerability
branch
from
May 30, 2025 02:45
8f97bcb to
c895ca1
Compare
|
/gcbrun |
renovate-bot
force-pushed
the
renovate/pypi-langchain-core-vulnerability
branch
from
May 30, 2025 11:51
c895ca1 to
1cb6047
Compare
|
/gcbrun |
renovate-bot
force-pushed
the
renovate/pypi-langchain-core-vulnerability
branch
from
May 30, 2025 21:29
1cb6047 to
1aea5dc
Compare
|
/gcbrun |
renovate-bot
force-pushed
the
renovate/pypi-langchain-core-vulnerability
branch
from
May 31, 2025 07:02
1aea5dc to
5c13305
Compare
|
/gcbrun |
renovate-bot
force-pushed
the
renovate/pypi-langchain-core-vulnerability
branch
from
May 31, 2025 14:28
5c13305 to
9596162
Compare
|
/gcbrun |
renovate-bot
force-pushed
the
renovate/pypi-langchain-core-vulnerability
branch
from
May 31, 2025 21:20
9596162 to
9e725a3
Compare
|
/gcbrun |
renovate-bot
force-pushed
the
renovate/pypi-langchain-core-vulnerability
branch
from
June 1, 2025 04:56
9e725a3 to
6033b01
Compare
|
/gcbrun |
renovate-bot
force-pushed
the
renovate/pypi-langchain-core-vulnerability
branch
from
June 1, 2025 13:43
6033b01 to
e168155
Compare
|
/gcbrun |
renovate-bot
force-pushed
the
renovate/pypi-langchain-core-vulnerability
branch
from
June 1, 2025 20:46
e168155 to
af93972
Compare
renovate-bot
force-pushed
the
renovate/pypi-langchain-core-vulnerability
branch
from
June 22, 2025 04:22
14928c7 to
5c8da62
Compare
|
/gcbrun |
renovate-bot
force-pushed
the
renovate/pypi-langchain-core-vulnerability
branch
from
June 22, 2025 14:50
5c8da62 to
658fb42
Compare
|
/gcbrun |
renovate-bot
force-pushed
the
renovate/pypi-langchain-core-vulnerability
branch
from
June 22, 2025 22:28
658fb42 to
ee724a8
Compare
|
/gcbrun |
renovate-bot
force-pushed
the
renovate/pypi-langchain-core-vulnerability
branch
from
June 23, 2025 08:28
ee724a8 to
c050041
Compare
|
/gcbrun |
renovate-bot
force-pushed
the
renovate/pypi-langchain-core-vulnerability
branch
from
June 23, 2025 22:51
c050041 to
741e1c4
Compare
|
/gcbrun |
17 similar comments
|
/gcbrun |
|
/gcbrun |
|
/gcbrun |
|
/gcbrun |
|
/gcbrun |
|
/gcbrun |
|
/gcbrun |
|
/gcbrun |
|
/gcbrun |
|
/gcbrun |
|
/gcbrun |
|
/gcbrun |
|
/gcbrun |
|
/gcbrun |
|
/gcbrun |
|
/gcbrun |
|
/gcbrun |
|
/gcbrun |
loeng2023
approved these changes
Jul 1, 2025
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
==0.3.6->==0.3.15GitHub Vulnerability Alerts
CVE-2024-10940
A vulnerability in langchain-core versions >=0.1.17,<0.1.53, >=0.2.0,<0.2.43, and >=0.3.0,<0.3.15 allows unauthorized users to read arbitrary files from the host file system. The issue arises from the ability to create langchain_core.prompts.ImagePromptTemplate's (and by extension langchain_core.prompts.ChatPromptTemplate's) with input variables that can read any user-specified path from the server file system. If the outputs of these prompt templates are exposed to the user, either directly or through downstream model outputs, it can lead to the exposure of sensitive information.
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Never, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.