← Scan another repo

github.com/langchain-ai/langchain

@ 1a43a6e14ab2

Submitted 8/4/2026, 10:25:52 AM · Status: ok

Risk grade
F
100 / 100
Findings
98
1 critical2 high93 medium2 low0 info0 on CISA KEV0ATT&CK
Showing 98 of 98 findings

Findings

  • ChromaDB Python project has a pre-authentication code injection vulnerability
    grypeCVE-2026-45829EPSS 12.4%
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • Ensure that arrays have a maximum number of items
    Ensure that arrays have a maximum number of items on paths
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/zapier/apispec.json:114
  • Ensure that arrays have a maximum number of items
    Ensure that arrays have a maximum number of items on paths
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/datasette/apispec.json:47
  • Ensure that arrays have a maximum number of items
    Ensure that arrays have a maximum number of items on paths
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/freetv-app/apispec.json:67
  • Ensure that arrays have a maximum number of items
    Ensure that arrays have a maximum number of items on paths
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/klarna/apispec.json:79
  • Ensure that arrays have a maximum number of items
    Ensure that arrays have a maximum number of items on paths
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/robot/apispec.yaml:23
  • Ensure that arrays have a maximum number of items
    Ensure that arrays have a maximum number of items on paths
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/schooldigger/apispec.json:787
  • Ensure that arrays have a maximum number of items
    Ensure that arrays have a maximum number of items on paths
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/shop/apispec.json:120
  • Ensure that arrays have a maximum number of items
    Ensure that arrays have a maximum number of items on paths
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/slack/apispec.json:71
  • Ensure that arrays have a maximum number of items
    Ensure that arrays have a maximum number of items on paths
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/wolframcloud/apispec.json:53
  • Ensure that arrays have a maximum number of items
    Ensure that arrays have a maximum number of items on paths
    checkovlibs/langchain/tests/integration_tests/examples/brandfetch-brandfetch-2.0.0-resolved.json:86
  • Ensure that arrays have a maximum number of items
    Ensure that arrays have a maximum number of items on paths
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/robot_openapi.yaml:23
  • Ensure that arrays have a maximum number of items
    Ensure that arrays have a maximum number of items on paths
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/apis-guru/apispec.json:54
  • Ensure that HEALTHCHECK instructions have been added to container images
    Ensure that HEALTHCHECK instructions have been added to container images on /libs/langchain/dev.Dockerfile.
    checkovlibs/langchain/dev.Dockerfile:1
  • Ensure that security operations is not empty.
    Ensure that security operations is not empty. on security
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/calculator/apispec.json:1
  • Ensure that security operations is not empty.
    Ensure that security operations is not empty. on security
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/datasette/apispec.json:1
  • Ensure that security operations is not empty.
    Ensure that security operations is not empty. on security
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/freetv-app/apispec.json:1
  • Ensure that security operations is not empty.
    Ensure that security operations is not empty. on security
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/joinmilo/apispec.json:1
  • Ensure that security operations is not empty.
    Ensure that security operations is not empty. on security
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/milo/apispec.json:1
  • Ensure that security operations is not empty.
    Ensure that security operations is not empty. on security
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/quickchart/apispec.json:1
  • Ensure that security operations is not empty.
    Ensure that security operations is not empty. on security
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/robot/apispec.yaml:1
  • Ensure that security operations is not empty.
    Ensure that security operations is not empty. on security
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/schooldigger/apispec.json:1
  • Ensure that security operations is not empty.
    Ensure that security operations is not empty. on security
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/shop/apispec.json:1
  • Ensure that security operations is not empty.
    Ensure that security operations is not empty. on security
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/slack/apispec.json:1
  • Ensure that security operations is not empty.
    Ensure that security operations is not empty. on security
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/speak/apispec.json:1
  • Ensure that security operations is not empty.
    Ensure that security operations is not empty. on security
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/wellknown/apispec.json:1
  • Ensure that security operations is not empty.
    Ensure that security operations is not empty. on security
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/wolframalpha/apispec.json:1
  • Ensure that security operations is not empty.
    Ensure that security operations is not empty. on security
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/wolframcloud/apispec.json:1
  • Ensure that security operations is not empty.
    Ensure that security operations is not empty. on security
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/klarna/apispec.json:1
  • Ensure that security operations is not empty.
    Ensure that security operations is not empty. on security
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/robot_openapi.yaml:1
  • Ensure that security operations is not empty.
    Ensure that security operations is not empty. on security
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/apis-guru/apispec.json:1
  • Ensure that security operations is not empty.
    Ensure that security operations is not empty. on security
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/biztoc/apispec.json:1
  • Ensure that security requirement defined in securityDefinitions - version 2.0 files
    Ensure that security requirement defined in securityDefinitions - version 2.0 files on security
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/schooldigger/apispec.json:1
  • Ensure that securityDefinitions is defined and not empty - version 2.0 files
    Ensure that securityDefinitions is defined and not empty - version 2.0 files on securityDefinitions
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/schooldigger/apispec.json:1
  • Ensure that the global security field has rules defined
    Ensure that the global security field has rules defined on security
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/datasette/apispec.json:1
  • Ensure that the global security field has rules defined
    Ensure that the global security field has rules defined on security
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/freetv-app/apispec.json:1
  • Ensure that the global security field has rules defined
    Ensure that the global security field has rules defined on security
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/joinmilo/apispec.json:1
  • Ensure that the global security field has rules defined
    Ensure that the global security field has rules defined on security
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/milo/apispec.json:1
  • Ensure that the global security field has rules defined
    Ensure that the global security field has rules defined on security
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/quickchart/apispec.json:1
  • Ensure that the global security field has rules defined
    Ensure that the global security field has rules defined on security
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/robot/apispec.yaml:1
  • Ensure that the global security field has rules defined
    Ensure that the global security field has rules defined on security
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/schooldigger/apispec.json:1
  • Ensure that the global security field has rules defined
    Ensure that the global security field has rules defined on security
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/shop/apispec.json:1
  • Ensure that the global security field has rules defined
    Ensure that the global security field has rules defined on security
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/slack/apispec.json:1
  • Ensure that the global security field has rules defined
    Ensure that the global security field has rules defined on security
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/speak/apispec.json:1
  • Ensure that the global security field has rules defined
    Ensure that the global security field has rules defined on security
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/urlbox/apispec.json:1
  • Ensure that the global security field has rules defined
    Ensure that the global security field has rules defined on security
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/wellknown/apispec.json:1
  • Ensure that the global security field has rules defined
    Ensure that the global security field has rules defined on security
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/wolframalpha/apispec.json:1
  • Ensure that the global security field has rules defined
    Ensure that the global security field has rules defined on security
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/wolframcloud/apispec.json:1
  • Ensure that the global security field has rules defined
    Ensure that the global security field has rules defined on security
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/zapier/apispec.json:1
  • Ensure that the global security field has rules defined
    Ensure that the global security field has rules defined on security
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/klarna/apispec.json:1
  • Ensure that the global security field has rules defined
    Ensure that the global security field has rules defined on security
    checkovlibs/langchain/tests/integration_tests/examples/brandfetch-brandfetch-2.0.0-resolved.json:1
  • Ensure that the global security field has rules defined
    Ensure that the global security field has rules defined on security
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/robot_openapi.yaml:1
  • Ensure that the global security field has rules defined
    Ensure that the global security field has rules defined on security
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/apis-guru/apispec.json:1
  • Ensure that the global security field has rules defined
    Ensure that the global security field has rules defined on security
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/biztoc/apispec.json:1
  • Ensure that the global security field has rules defined
    Ensure that the global security field has rules defined on security
    checkovlibs/langchain/tests/unit_tests/examples/test_specs/calculator/apispec.json:1
  • The build output cannot be affected by user parameters other than the build entry point and the top-level source location. GitHub Actions workflow_dispatch inputs MUST be empty.
    The build output cannot be affected by user parameters other than the build entry point and the top-level source location. GitHub Actions workflow_dispatch inputs MUST be empty. on on(🚀 Package Release)
    checkov.github/workflows/_release.yml:55
  • The build output cannot be affected by user parameters other than the build entry point and the top-level source location. GitHub Actions workflow_dispatch inputs MUST be empty.
    The build output cannot be affected by user parameters other than the build entry point and the top-level source location. GitHub Actions workflow_dispatch inputs MUST be empty. on on(⏰ Integration Tests)
    checkov.github/workflows/integration_tests.yml:13
  • The build output cannot be affected by user parameters other than the build entry point and the top-level source location. GitHub Actions workflow_dispatch inputs MUST be empty.
    The build output cannot be affected by user parameters other than the build entry point and the top-level source location. GitHub Actions workflow_dispatch inputs MUST be empty. on on(🏷️ PR Labeler Backfill)
    checkov.github/workflows/pr_labeler_backfill.yml:12
  • The build output cannot be affected by user parameters other than the build entry point and the top-level source location. GitHub Actions workflow_dispatch inputs MUST be empty.
    The build output cannot be affected by user parameters other than the build entry point and the top-level source location. GitHub Actions workflow_dispatch inputs MUST be empty. on on(🔄 Refresh Model Profiles)
    checkov.github/workflows/refresh_model_profiles.yml:15
  • The build output cannot be affected by user parameters other than the build entry point and the top-level source location. GitHub Actions workflow_dispatch inputs MUST be empty.
    The build output cannot be affected by user parameters other than the build entry point and the top-level source location. GitHub Actions workflow_dispatch inputs MUST be empty. on on(Tag External Issues)
    checkov.github/workflows/tag-external-issues.yml:33
  • setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+
    grypeCVE-2026-59890EPSS 0.4%
  • ChromaDB Python project has a pre-authentication code injection vulnerability
    A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in the /api/v2/tenants/{ten…
    osv-scannerCVE-2026-45829
  • ChromaDB Python project has a pre-authentication code injection vulnerability
    A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in the /api/v2/tenants/{ten…
    osv-scannerCVE-2026-45829
  • PYSEC-2026-2132
    Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.
    osv-scannerCVE-2026-7246
  • PYSEC-2026-2132
    Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.
    osv-scannerCVE-2026-7246
  • PYSEC-2026-2132
    Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.
    osv-scannerCVE-2026-7246
  • PYSEC-2026-2132
    Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.
    osv-scannerCVE-2026-7246
  • PYSEC-2026-2132
    Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.
    osv-scannerCVE-2026-7246
  • PYSEC-2026-2132
    Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.
    osv-scannerCVE-2026-7246
  • PYSEC-2026-3447
    setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compiled glob patterns against on-disk file na…
    osv-scannerCVE-2026-59890
  • setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+
    ## Summary When building a source distribution (`python -m build --sdist` / `setup.py sdist`), setuptools' `FileList` applies `MANIFEST.in` directives (`exclude`, `global-exclude`, `recursive-exclude`, `prune`) by matching a compiled glob against on-disk file names **byte-for-by…
    osv-scannerCVE-2026-59890
  • hashlib.md5/sha1 is broken for security use. Use sha256+ or a password KDF (bcrypt/scrypt/argon2). (Apache-2.0.)
    hashlib.md5/sha1 is broken for security use. Use sha256+ or a password KDF (bcrypt/scrypt/argon2). (Apache-2.0.)
    semgreplibs/core/langchain_core/indexing/api.py:46
  • hashlib.md5/sha1 is broken for security use. Use sha256+ or a password KDF (bcrypt/scrypt/argon2). (Apache-2.0.)
    hashlib.md5/sha1 is broken for security use. Use sha256+ or a password KDF (bcrypt/scrypt/argon2). (Apache-2.0.)
    semgreplibs/core/langchain_core/indexing/api.py:163
  • hashlib.md5/sha1 is broken for security use. Use sha256+ or a password KDF (bcrypt/scrypt/argon2). (Apache-2.0.)
    hashlib.md5/sha1 is broken for security use. Use sha256+ or a password KDF (bcrypt/scrypt/argon2). (Apache-2.0.)
    semgreplibs/langchain/langchain_classic/embeddings/cache.py:38
  • Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    semgreplibs/partners/xai/langchain_xai/chat_models.py:72
  • Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    semgreplibs/partners/fireworks/langchain_fireworks/embeddings.py:18
  • Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    semgreplibs/partners/groq/langchain_groq/chat_models.py:141
  • Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    semgreplibs/partners/huggingface/langchain_huggingface/embeddings/huggingface_endpoint.py:30
  • Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    semgreplibs/partners/huggingface/langchain_huggingface/llms/huggingface_endpoint.py:63
  • Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    semgreplibs/partners/huggingface/langchain_huggingface/llms/huggingface_endpoint.py:81
  • Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    semgreplibs/partners/huggingface/langchain_huggingface/llms/huggingface_endpoint.py:91
  • Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    semgreplibs/partners/mistralai/langchain_mistralai/embeddings.py:68
  • Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    semgreplibs/partners/openai/langchain_openai/chat_models/azure.py:50
  • Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    semgreplibs/partners/openai/langchain_openai/chat_models/base.py:2654
  • Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    semgreplibs/partners/openai/langchain_openai/chat_models/base.py:3289
  • Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    semgreplibs/partners/openai/langchain_openai/embeddings/azure.py:35
  • Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    semgreplibs/partners/openai/langchain_openai/embeddings/base.py:94
  • Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    semgreplibs/partners/openai/langchain_openai/llms/base.py:65
  • Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    semgreplibs/partners/openai/langchain_openai/llms/base.py:795
  • Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    semgreplibs/partners/openai/scripts/record_codex_cassettes.sh:112
  • Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    semgreplibs/partners/openrouter/langchain_openrouter/chat_models.py:120
  • Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    semgreplibs/partners/anthropic/langchain_anthropic/chat_models.py:917
  • Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    semgreplibs/partners/deepseek/langchain_deepseek/chat_models.py:56
  • Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    semgreplibs/partners/exa/langchain_exa/tools.py:29

This report is public.