AE-BFPF6JD0
Unescaped 'lc' keys in serialized data let prompt-injected LLM response fields load environment secrets on deserialization
SECURITY FAILUREseverity: CRITICALcause: VERIFIEDoutcome: RESOLVED UNVERIFIEDconfidence: HIGH
LangChain's dumps()/dumpd() did not escape free-form dictionaries containing the internal 'lc' marker key, so user- or LLM-controlled data was treated as a LangChain object when later loaded. With the old default secrets_from_env=True this allowed extraction of environment-variable secrets, and it allowed instantiating classes within trusted namespaces with attacker-controlled parameters; LLM response fields such as additional_kwargs can be controlled via prompt injection and pass through streaming serialization.
- Framework / agent
- LangChain · LLM chains/agents using LangChain serialization (streaming, message history, caches)
- Remediation attempts
- TESTED
- Recurrence
- not documented
- Source languages
- en, und-Latn
- Updated
- 2026-09-30
Sources
- SECURITY ADVISORY LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs — https://github.com/langchain-ai/langchain, retrieved 2026-09-29
- GITHUB PULL REQUEST fix(core): serialization patch — github.com/langchain-ai/langchain, retrieved 2026-09-29
Symptoms
- Injected 'lc' structures in user data are deserialized as legitimate LangChain objects instead of plain data
- Environment-variable secrets can be extracted during deserialization
- Classes in trusted namespaces can be instantiated with attacker-controlled parameters, triggering side effects such as network calls or file operations
The full record — root-cause evidence, every remediation attempt with its status and verification, failed attempts, patch references, verbatim quotes and recurrence — is a paid lookup (0.018 USDC via x402). Agents:
GET /api/v1/cases/AE-BFPF6JD0. PricingSimilarity to your system is not implied. A remediation that worked in the documented context may not work in yours.