chore(deps): update dependency langchain-community to v0.3.27 [security] - autoclosed#97
Closed
renovate-bot wants to merge 1 commit intogoogleapis:mainfrom
Closed
Conversation
|
/gcbrun |
9dc316c to
f9e7752
Compare
|
/gcbrun |
f9e7752 to
2950acc
Compare
|
/gcbrun |
2950acc to
a85b3d9
Compare
|
/gcbrun |
a85b3d9 to
c0e8999
Compare
|
/gcbrun |
c0e8999 to
1c6dc1d
Compare
|
/gcbrun |
1c6dc1d to
5b722c0
Compare
|
/gcbrun |
5b722c0 to
5338dc7
Compare
|
/gcbrun |
5338dc7 to
edd22eb
Compare
|
/gcbrun |
edd22eb to
053a0e5
Compare
|
/gcbrun |
053a0e5 to
f6d479a
Compare
|
/gcbrun |
f6d479a to
4536fc9
Compare
|
/gcbrun |
4536fc9 to
a223ff7
Compare
|
/gcbrun |
a223ff7 to
4e188c7
Compare
7239a62 to
5070e99
Compare
|
/gcbrun |
5070e99 to
1d9c642
Compare
|
/gcbrun |
1d9c642 to
5a0fe5e
Compare
|
/gcbrun |
5a0fe5e to
d0e94d5
Compare
|
/gcbrun |
20 similar comments
|
/gcbrun |
|
/gcbrun |
|
/gcbrun |
|
/gcbrun |
|
/gcbrun |
|
/gcbrun |
|
/gcbrun |
|
/gcbrun |
|
/gcbrun |
|
/gcbrun |
|
/gcbrun |
|
/gcbrun |
|
/gcbrun |
|
/gcbrun |
|
/gcbrun |
|
/gcbrun |
|
/gcbrun |
|
/gcbrun |
|
/gcbrun |
|
/gcbrun |
|
/gcbrun |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
==0.3.3->==0.3.27GitHub Vulnerability Alerts
CVE-2025-6984
The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The vulnerability arises from the use of etree.iterparse() without disabling external entity references, which can lead to sensitive information disclosure. An attacker could exploit this by crafting a malicious XML payload that references local files, potentially exposing sensitive data such as /etc/passwd. This issue has been fixed in 0.3.27 of langchain-community.
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Never, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.