github.com/langchain-ai/langchain
Submitted 8/4/2026, 10:25:52 AM · Status: ok
Risk grade
F
100 / 100
Findings
98
1 critical2 high93 medium2 low0 info0 on CISA KEV0ATT&CK
Showing 98 of 98 findings
Findings
- ChromaDB Python project has a pre-authentication code injection vulnerabilitygrypeCVE-2026-45829EPSS 12.4%
- Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operationsDetected a Generic API Key, potentially exposing access to various services and sensitive operations.gitleaks
- Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operationsDetected a Generic API Key, potentially exposing access to various services and sensitive operations.gitleaks
- Ensure that arrays have a maximum number of itemsEnsure that arrays have a maximum number of items on pathscheckovlibs/langchain/tests/unit_tests/examples/test_specs/zapier/apispec.json:114
- Ensure that arrays have a maximum number of itemsEnsure that arrays have a maximum number of items on pathscheckovlibs/langchain/tests/unit_tests/examples/test_specs/datasette/apispec.json:47
- Ensure that arrays have a maximum number of itemsEnsure that arrays have a maximum number of items on pathscheckovlibs/langchain/tests/unit_tests/examples/test_specs/freetv-app/apispec.json:67
- Ensure that arrays have a maximum number of itemsEnsure that arrays have a maximum number of items on pathscheckovlibs/langchain/tests/unit_tests/examples/test_specs/klarna/apispec.json:79
- Ensure that arrays have a maximum number of itemsEnsure that arrays have a maximum number of items on pathscheckovlibs/langchain/tests/unit_tests/examples/test_specs/robot/apispec.yaml:23
- Ensure that arrays have a maximum number of itemsEnsure that arrays have a maximum number of items on pathscheckovlibs/langchain/tests/unit_tests/examples/test_specs/schooldigger/apispec.json:787
- Ensure that arrays have a maximum number of itemsEnsure that arrays have a maximum number of items on pathscheckovlibs/langchain/tests/unit_tests/examples/test_specs/shop/apispec.json:120
- Ensure that arrays have a maximum number of itemsEnsure that arrays have a maximum number of items on pathscheckovlibs/langchain/tests/unit_tests/examples/test_specs/slack/apispec.json:71
- Ensure that arrays have a maximum number of itemsEnsure that arrays have a maximum number of items on pathscheckovlibs/langchain/tests/unit_tests/examples/test_specs/wolframcloud/apispec.json:53
- Ensure that arrays have a maximum number of itemsEnsure that arrays have a maximum number of items on pathscheckovlibs/langchain/tests/integration_tests/examples/brandfetch-brandfetch-2.0.0-resolved.json:86
- Ensure that arrays have a maximum number of itemsEnsure that arrays have a maximum number of items on pathscheckovlibs/langchain/tests/unit_tests/examples/test_specs/robot_openapi.yaml:23
- Ensure that arrays have a maximum number of itemsEnsure that arrays have a maximum number of items on pathscheckovlibs/langchain/tests/unit_tests/examples/test_specs/apis-guru/apispec.json:54
- Ensure that HEALTHCHECK instructions have been added to container imagesEnsure that HEALTHCHECK instructions have been added to container images on /libs/langchain/dev.Dockerfile.checkovlibs/langchain/dev.Dockerfile:1
- Ensure that security operations is not empty.Ensure that security operations is not empty. on securitycheckovlibs/langchain/tests/unit_tests/examples/test_specs/calculator/apispec.json:1
- Ensure that security operations is not empty.Ensure that security operations is not empty. on securitycheckovlibs/langchain/tests/unit_tests/examples/test_specs/datasette/apispec.json:1
- Ensure that security operations is not empty.Ensure that security operations is not empty. on securitycheckovlibs/langchain/tests/unit_tests/examples/test_specs/freetv-app/apispec.json:1
- Ensure that security operations is not empty.Ensure that security operations is not empty. on securitycheckovlibs/langchain/tests/unit_tests/examples/test_specs/joinmilo/apispec.json:1
- Ensure that security operations is not empty.Ensure that security operations is not empty. on securitycheckovlibs/langchain/tests/unit_tests/examples/test_specs/milo/apispec.json:1
- Ensure that security operations is not empty.Ensure that security operations is not empty. on securitycheckovlibs/langchain/tests/unit_tests/examples/test_specs/quickchart/apispec.json:1
- Ensure that security operations is not empty.Ensure that security operations is not empty. on securitycheckovlibs/langchain/tests/unit_tests/examples/test_specs/robot/apispec.yaml:1
- Ensure that security operations is not empty.Ensure that security operations is not empty. on securitycheckovlibs/langchain/tests/unit_tests/examples/test_specs/schooldigger/apispec.json:1
- Ensure that security operations is not empty.Ensure that security operations is not empty. on securitycheckovlibs/langchain/tests/unit_tests/examples/test_specs/shop/apispec.json:1
- Ensure that security operations is not empty.Ensure that security operations is not empty. on securitycheckovlibs/langchain/tests/unit_tests/examples/test_specs/slack/apispec.json:1
- Ensure that security operations is not empty.Ensure that security operations is not empty. on securitycheckovlibs/langchain/tests/unit_tests/examples/test_specs/speak/apispec.json:1
- Ensure that security operations is not empty.Ensure that security operations is not empty. on securitycheckovlibs/langchain/tests/unit_tests/examples/test_specs/wellknown/apispec.json:1
- Ensure that security operations is not empty.Ensure that security operations is not empty. on securitycheckovlibs/langchain/tests/unit_tests/examples/test_specs/wolframalpha/apispec.json:1
- Ensure that security operations is not empty.Ensure that security operations is not empty. on securitycheckovlibs/langchain/tests/unit_tests/examples/test_specs/wolframcloud/apispec.json:1
- Ensure that security operations is not empty.Ensure that security operations is not empty. on securitycheckovlibs/langchain/tests/unit_tests/examples/test_specs/klarna/apispec.json:1
- Ensure that security operations is not empty.Ensure that security operations is not empty. on securitycheckovlibs/langchain/tests/unit_tests/examples/test_specs/robot_openapi.yaml:1
- Ensure that security operations is not empty.Ensure that security operations is not empty. on securitycheckovlibs/langchain/tests/unit_tests/examples/test_specs/apis-guru/apispec.json:1
- Ensure that security operations is not empty.Ensure that security operations is not empty. on securitycheckovlibs/langchain/tests/unit_tests/examples/test_specs/biztoc/apispec.json:1
- Ensure that security requirement defined in securityDefinitions - version 2.0 filesEnsure that security requirement defined in securityDefinitions - version 2.0 files on securitycheckovlibs/langchain/tests/unit_tests/examples/test_specs/schooldigger/apispec.json:1
- Ensure that securityDefinitions is defined and not empty - version 2.0 filesEnsure that securityDefinitions is defined and not empty - version 2.0 files on securityDefinitionscheckovlibs/langchain/tests/unit_tests/examples/test_specs/schooldigger/apispec.json:1
- Ensure that the global security field has rules definedEnsure that the global security field has rules defined on securitycheckovlibs/langchain/tests/unit_tests/examples/test_specs/datasette/apispec.json:1
- Ensure that the global security field has rules definedEnsure that the global security field has rules defined on securitycheckovlibs/langchain/tests/unit_tests/examples/test_specs/freetv-app/apispec.json:1
- Ensure that the global security field has rules definedEnsure that the global security field has rules defined on securitycheckovlibs/langchain/tests/unit_tests/examples/test_specs/joinmilo/apispec.json:1
- Ensure that the global security field has rules definedEnsure that the global security field has rules defined on securitycheckovlibs/langchain/tests/unit_tests/examples/test_specs/milo/apispec.json:1
- Ensure that the global security field has rules definedEnsure that the global security field has rules defined on securitycheckovlibs/langchain/tests/unit_tests/examples/test_specs/quickchart/apispec.json:1
- Ensure that the global security field has rules definedEnsure that the global security field has rules defined on securitycheckovlibs/langchain/tests/unit_tests/examples/test_specs/robot/apispec.yaml:1
- Ensure that the global security field has rules definedEnsure that the global security field has rules defined on securitycheckovlibs/langchain/tests/unit_tests/examples/test_specs/schooldigger/apispec.json:1
- Ensure that the global security field has rules definedEnsure that the global security field has rules defined on securitycheckovlibs/langchain/tests/unit_tests/examples/test_specs/shop/apispec.json:1
- Ensure that the global security field has rules definedEnsure that the global security field has rules defined on securitycheckovlibs/langchain/tests/unit_tests/examples/test_specs/slack/apispec.json:1
- Ensure that the global security field has rules definedEnsure that the global security field has rules defined on securitycheckovlibs/langchain/tests/unit_tests/examples/test_specs/speak/apispec.json:1
- Ensure that the global security field has rules definedEnsure that the global security field has rules defined on securitycheckovlibs/langchain/tests/unit_tests/examples/test_specs/urlbox/apispec.json:1
- Ensure that the global security field has rules definedEnsure that the global security field has rules defined on securitycheckovlibs/langchain/tests/unit_tests/examples/test_specs/wellknown/apispec.json:1
- Ensure that the global security field has rules definedEnsure that the global security field has rules defined on securitycheckovlibs/langchain/tests/unit_tests/examples/test_specs/wolframalpha/apispec.json:1
- Ensure that the global security field has rules definedEnsure that the global security field has rules defined on securitycheckovlibs/langchain/tests/unit_tests/examples/test_specs/wolframcloud/apispec.json:1
- Ensure that the global security field has rules definedEnsure that the global security field has rules defined on securitycheckovlibs/langchain/tests/unit_tests/examples/test_specs/zapier/apispec.json:1
- Ensure that the global security field has rules definedEnsure that the global security field has rules defined on securitycheckovlibs/langchain/tests/unit_tests/examples/test_specs/klarna/apispec.json:1
- Ensure that the global security field has rules definedEnsure that the global security field has rules defined on securitycheckovlibs/langchain/tests/integration_tests/examples/brandfetch-brandfetch-2.0.0-resolved.json:1
- Ensure that the global security field has rules definedEnsure that the global security field has rules defined on securitycheckovlibs/langchain/tests/unit_tests/examples/test_specs/robot_openapi.yaml:1
- Ensure that the global security field has rules definedEnsure that the global security field has rules defined on securitycheckovlibs/langchain/tests/unit_tests/examples/test_specs/apis-guru/apispec.json:1
- Ensure that the global security field has rules definedEnsure that the global security field has rules defined on securitycheckovlibs/langchain/tests/unit_tests/examples/test_specs/biztoc/apispec.json:1
- Ensure that the global security field has rules definedEnsure that the global security field has rules defined on securitycheckovlibs/langchain/tests/unit_tests/examples/test_specs/calculator/apispec.json:1
- The build output cannot be affected by user parameters other than the build entry point and the top-level source location. GitHub Actions workflow_dispatch inputs MUST be empty.The build output cannot be affected by user parameters other than the build entry point and the top-level source location. GitHub Actions workflow_dispatch inputs MUST be empty. on on(🚀 Package Release)checkov.github/workflows/_release.yml:55
- The build output cannot be affected by user parameters other than the build entry point and the top-level source location. GitHub Actions workflow_dispatch inputs MUST be empty.The build output cannot be affected by user parameters other than the build entry point and the top-level source location. GitHub Actions workflow_dispatch inputs MUST be empty. on on(⏰ Integration Tests)checkov.github/workflows/integration_tests.yml:13
- The build output cannot be affected by user parameters other than the build entry point and the top-level source location. GitHub Actions workflow_dispatch inputs MUST be empty.The build output cannot be affected by user parameters other than the build entry point and the top-level source location. GitHub Actions workflow_dispatch inputs MUST be empty. on on(🏷️ PR Labeler Backfill)checkov.github/workflows/pr_labeler_backfill.yml:12
- The build output cannot be affected by user parameters other than the build entry point and the top-level source location. GitHub Actions workflow_dispatch inputs MUST be empty.The build output cannot be affected by user parameters other than the build entry point and the top-level source location. GitHub Actions workflow_dispatch inputs MUST be empty. on on(🔄 Refresh Model Profiles)checkov.github/workflows/refresh_model_profiles.yml:15
- The build output cannot be affected by user parameters other than the build entry point and the top-level source location. GitHub Actions workflow_dispatch inputs MUST be empty.The build output cannot be affected by user parameters other than the build entry point and the top-level source location. GitHub Actions workflow_dispatch inputs MUST be empty. on on(Tag External Issues)checkov.github/workflows/tag-external-issues.yml:33
- setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+grypeCVE-2026-59890EPSS 0.4%
- ChromaDB Python project has a pre-authentication code injection vulnerabilityA pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in the /api/v2/tenants/{ten…osv-scannerCVE-2026-45829
- ChromaDB Python project has a pre-authentication code injection vulnerabilityA pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in the /api/v2/tenants/{ten…osv-scannerCVE-2026-45829
- PYSEC-2026-2132Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.osv-scannerCVE-2026-7246
- PYSEC-2026-2132Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.osv-scannerCVE-2026-7246
- PYSEC-2026-2132Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.osv-scannerCVE-2026-7246
- PYSEC-2026-2132Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.osv-scannerCVE-2026-7246
- PYSEC-2026-2132Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.osv-scannerCVE-2026-7246
- PYSEC-2026-2132Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.osv-scannerCVE-2026-7246
- PYSEC-2026-3447setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compiled glob patterns against on-disk file na…osv-scannerCVE-2026-59890
- setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+## Summary When building a source distribution (`python -m build --sdist` / `setup.py sdist`), setuptools' `FileList` applies `MANIFEST.in` directives (`exclude`, `global-exclude`, `recursive-exclude`, `prune`) by matching a compiled glob against on-disk file names **byte-for-by…osv-scannerCVE-2026-59890
- hashlib.md5/sha1 is broken for security use. Use sha256+ or a password KDF (bcrypt/scrypt/argon2). (Apache-2.0.)hashlib.md5/sha1 is broken for security use. Use sha256+ or a password KDF (bcrypt/scrypt/argon2). (Apache-2.0.)semgreplibs/core/langchain_core/indexing/api.py:46
- hashlib.md5/sha1 is broken for security use. Use sha256+ or a password KDF (bcrypt/scrypt/argon2). (Apache-2.0.)hashlib.md5/sha1 is broken for security use. Use sha256+ or a password KDF (bcrypt/scrypt/argon2). (Apache-2.0.)semgreplibs/core/langchain_core/indexing/api.py:163
- hashlib.md5/sha1 is broken for security use. Use sha256+ or a password KDF (bcrypt/scrypt/argon2). (Apache-2.0.)hashlib.md5/sha1 is broken for security use. Use sha256+ or a password KDF (bcrypt/scrypt/argon2). (Apache-2.0.)semgreplibs/langchain/langchain_classic/embeddings/cache.py:38
- Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)semgreplibs/partners/xai/langchain_xai/chat_models.py:72
- Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)semgreplibs/partners/fireworks/langchain_fireworks/embeddings.py:18
- Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)semgreplibs/partners/groq/langchain_groq/chat_models.py:141
- Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)semgreplibs/partners/huggingface/langchain_huggingface/embeddings/huggingface_endpoint.py:30
- Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)semgreplibs/partners/huggingface/langchain_huggingface/llms/huggingface_endpoint.py:63
- Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)semgreplibs/partners/huggingface/langchain_huggingface/llms/huggingface_endpoint.py:81
- Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)semgreplibs/partners/huggingface/langchain_huggingface/llms/huggingface_endpoint.py:91
- Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)semgreplibs/partners/mistralai/langchain_mistralai/embeddings.py:68
- Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)semgreplibs/partners/openai/langchain_openai/chat_models/azure.py:50
- Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)semgreplibs/partners/openai/langchain_openai/chat_models/base.py:2654
- Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)semgreplibs/partners/openai/langchain_openai/chat_models/base.py:3289
- Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)semgreplibs/partners/openai/langchain_openai/embeddings/azure.py:35
- Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)semgreplibs/partners/openai/langchain_openai/embeddings/base.py:94
- Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)semgreplibs/partners/openai/langchain_openai/llms/base.py:65
- Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)semgreplibs/partners/openai/langchain_openai/llms/base.py:795
- Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)semgreplibs/partners/openai/scripts/record_codex_cassettes.sh:112
- Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)semgreplibs/partners/openrouter/langchain_openrouter/chat_models.py:120
- Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)semgreplibs/partners/anthropic/langchain_anthropic/chat_models.py:917
- Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)semgreplibs/partners/deepseek/langchain_deepseek/chat_models.py:56
- Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)semgreplibs/partners/exa/langchain_exa/tools.py:29
This report is public.