Commit 8dae1bf
security: 升级 langchain-core 到 0.3.81 修复 CVE-2025-68664 (#403)
- 修复序列化注入漏洞 (GHSA-c67j-w6g6-q2cm)
- 从 0.3.68 升级到 0.3.81 (小版本升级)
- 影响评估: 无破坏性变更,向后兼容
- 安全加固: 默认禁用环境变量加载,限制反序列化类
Fixes Dependabot Alert #23
Resolves CVE-2025-68664
Co-authored-by: Claude Sonnet 4.5 <noreply@anthropic.com>1 parent 007e994 commit 8dae1bf
1 file changed
+2
-2
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | | - | |
| 2 | + | |
3 | 3 | | |
4 | | - | |
| 4 | + | |
0 commit comments