CVE-2026-26013 PUBLISHED CVSS 3.700000047683716 LOW

LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages

EPSS 0.02% · 4.7th percentile

Risk Scores

CVSS v3.1
3.700000047683716
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
EPSS Score
0.02%
4.7th percentile

Affected Products

VendorProductVersions
langchainlangchain_core0
langchain-ailangchain< 1.2.11
PyPIlangchain-core0

Timeline

References

Open in Interactive Console →