Commit aa6c244
committed
fix(deps): bump langchain-core to ^1.2.5 to address CVE-2025-68664
This addresses the critical serialization injection vulnerability
(GHSA-c67j-w6g6-q2cm / CVE-2025-68664) in langchain-core that allows
attackers to steal secrets via the dumps/loads APIs.
Fixed versions: 0.3.81+ (0.x branch) or 1.2.5+ (1.x branch)
Related oncall issue: airbytehq/oncall#10773
Co-Authored-By: unknown <>1 parent 49ff36e commit aa6c244
2 files changed
Lines changed: 39 additions & 5 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
64 | 64 | | |
65 | 65 | | |
66 | 66 | | |
67 | | - | |
| 67 | + | |
68 | 68 | | |
69 | 69 | | |
70 | 70 | | |
| |||
0 commit comments