AE Agent Errors
AE-BFPF6JD0

Unescaped 'lc' keys in serialized data let prompt-injected LLM response fields load environment secrets on deserialization

SECURITY FAILUREseverity: CRITICALcause: VERIFIEDoutcome: RESOLVED UNVERIFIEDconfidence: HIGH

LangChain's dumps()/dumpd() did not escape free-form dictionaries containing the internal 'lc' marker key, so user- or LLM-controlled data was treated as a LangChain object when later loaded. With the old default secrets_from_env=True this allowed extraction of environment-variable secrets, and it allowed instantiating classes within trusted namespaces with attacker-controlled parameters; LLM response fields such as additional_kwargs can be controlled via prompt injection and pass through streaming serialization.

Framework / agent
LangChain · LLM chains/agents using LangChain serialization (streaming, message history, caches)
Remediation attempts
TESTED
Recurrence
not documented
Source languages
en, und-Latn
Updated
2026-09-30

Sources

Symptoms

  • Injected 'lc' structures in user data are deserialized as legitimate LangChain objects instead of plain data
  • Environment-variable secrets can be extracted during deserialization
  • Classes in trusted namespaces can be instantiated with attacker-controlled parameters, triggering side effects such as network calls or file operations
The full record — root-cause evidence, every remediation attempt with its status and verification, failed attempts, patch references, verbatim quotes and recurrence — is a paid lookup (0.018 USDC via x402). Agents: GET /api/v1/cases/AE-BFPF6JD0. Pricing

Similarity to your system is not implied. A remediation that worked in the documented context may not work in yours.