Skip to content

chore(deps): update dependency langchain-core to v0.1.53 [security]#83

Open
renovate-bot wants to merge 1 commit intogoogleapis:mainfrom
renovate-bot:renovate/pypi-langchain-core-vulnerability
Open

chore(deps): update dependency langchain-core to v0.1.53 [security]#83
renovate-bot wants to merge 1 commit intogoogleapis:mainfrom
renovate-bot:renovate/pypi-langchain-core-vulnerability

Conversation

@renovate-bot
Copy link
Contributor

@renovate-bot renovate-bot commented Mar 21, 2025

This PR contains the following updates:

Package Change Age Confidence
langchain-core (changelog) ==0.1.45 -> ==0.1.53 age confidence

GitHub Vulnerability Alerts

CVE-2024-10940

A vulnerability in langchain-core versions >=0.1.17,<0.1.53, >=0.2.0,<0.2.43, and >=0.3.0,<0.3.15 allows unauthorized users to read arbitrary files from the host file system. The issue arises from the ability to create langchain_core.prompts.ImagePromptTemplate's (and by extension langchain_core.prompts.ChatPromptTemplate's) with input variables that can read any user-specified path from the server file system. If the outputs of these prompt templates are exposed to the user, either directly or through downstream model outputs, it can lead to the exposure of sensitive information.


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Never, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate-bot renovate-bot requested review from a team March 21, 2025 16:52
@dpebot
Copy link

dpebot commented Mar 21, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from c1db2ca to bb385b0 Compare May 28, 2025 08:21
@dpebot
Copy link

dpebot commented May 28, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from bb385b0 to 3e10db5 Compare May 28, 2025 23:00
@dpebot
Copy link

dpebot commented May 28, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from 3e10db5 to 73dbb6a Compare May 29, 2025 04:41
@dpebot
Copy link

dpebot commented May 29, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from 73dbb6a to 35e5795 Compare May 29, 2025 13:11
@dpebot
Copy link

dpebot commented May 29, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from 35e5795 to c6095ed Compare May 30, 2025 00:21
@dpebot
Copy link

dpebot commented May 30, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from c6095ed to 4433383 Compare May 30, 2025 12:24
@dpebot
Copy link

dpebot commented May 30, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from 4433383 to 1b4f9c1 Compare May 31, 2025 01:36
@dpebot
Copy link

dpebot commented May 31, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from 1b4f9c1 to 62a57ea Compare May 31, 2025 09:23
@dpebot
Copy link

dpebot commented May 31, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from 62a57ea to cf06352 Compare May 31, 2025 17:08
@dpebot
Copy link

dpebot commented May 31, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from cf06352 to 3ba40d1 Compare June 1, 2025 02:34
@dpebot
Copy link

dpebot commented Jun 1, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from 3ba40d1 to dfc01c2 Compare June 1, 2025 11:13
@dpebot
Copy link

dpebot commented Jun 1, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from dfc01c2 to bc40e3f Compare June 1, 2025 17:51
@dpebot
Copy link

dpebot commented Jun 1, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from bc40e3f to 987cb63 Compare June 2, 2025 02:57
@dpebot
Copy link

dpebot commented Jun 2, 2025

/gcbrun

@dpebot
Copy link

dpebot commented Sep 27, 2025

/gcbrun

27 similar comments
@dpebot
Copy link

dpebot commented Sep 28, 2025

/gcbrun

@dpebot
Copy link

dpebot commented Sep 28, 2025

/gcbrun

@dpebot
Copy link

dpebot commented Sep 28, 2025

/gcbrun

@dpebot
Copy link

dpebot commented Sep 29, 2025

/gcbrun

@dpebot
Copy link

dpebot commented Sep 29, 2025

/gcbrun

@dpebot
Copy link

dpebot commented Sep 29, 2025

/gcbrun

@dpebot
Copy link

dpebot commented Sep 30, 2025

/gcbrun

@dpebot
Copy link

dpebot commented Sep 30, 2025

/gcbrun

@dpebot
Copy link

dpebot commented Oct 1, 2025

/gcbrun

@dpebot
Copy link

dpebot commented Oct 2, 2025

/gcbrun

@dpebot
Copy link

dpebot commented Oct 2, 2025

/gcbrun

@dpebot
Copy link

dpebot commented Oct 3, 2025

/gcbrun

@dpebot
Copy link

dpebot commented Oct 3, 2025

/gcbrun

@dpebot
Copy link

dpebot commented Oct 3, 2025

/gcbrun

@dpebot
Copy link

dpebot commented Oct 4, 2025

/gcbrun

@dpebot
Copy link

dpebot commented Oct 4, 2025

/gcbrun

@dpebot
Copy link

dpebot commented Oct 4, 2025

/gcbrun

@dpebot
Copy link

dpebot commented Oct 5, 2025

/gcbrun

@dpebot
Copy link

dpebot commented Oct 5, 2025

/gcbrun

@dpebot
Copy link

dpebot commented Oct 5, 2025

/gcbrun

@dpebot
Copy link

dpebot commented Oct 6, 2025

/gcbrun

@dpebot
Copy link

dpebot commented Oct 6, 2025

/gcbrun

@dpebot
Copy link

dpebot commented Oct 6, 2025

/gcbrun

@dpebot
Copy link

dpebot commented Oct 7, 2025

/gcbrun

@dpebot
Copy link

dpebot commented Oct 7, 2025

/gcbrun

@dpebot
Copy link

dpebot commented Oct 8, 2025

/gcbrun

@dpebot
Copy link

dpebot commented Oct 8, 2025

/gcbrun

@dpebot
Copy link

dpebot commented Oct 9, 2025

/gcbrun

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants