The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The affected version is 0.3.63. The vulnerability arises from the use of etree.iterparse() without disabling external entity references, which can lead to sensitive information disclosure. An attacker could exploit this by crafting a malicious XML payload that references local files, potentially exposing sensitive data such as /etc/passwd.
History

Fri, 05 Sep 2025 00:15:00 +0000


Thu, 04 Sep 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 04 Sep 2025 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Langchain-ai
Langchain-ai langchain
Vendors & Products Langchain-ai
Langchain-ai langchain

Thu, 04 Sep 2025 08:15:00 +0000

Type Values Removed Values Added
Description The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The affected version is 0.3.63. The vulnerability arises from the use of etree.iterparse() without disabling external entity references, which can lead to sensitive information disclosure. An attacker could exploit this by crafting a malicious XML payload that references local files, potentially exposing sensitive data such as /etc/passwd.
Title Sensitive Information Disclosure Due to Insecure XML Parsing in langchain-ai/langchain
Weaknesses CWE-200
References
Metrics cvssV3_0

{'score': 7.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published: 2025-09-04T08:07:41.996Z

Updated: 2025-09-04T20:07:31.531Z

Reserved: 2025-07-01T20:19:39.922Z

Link: CVE-2025-6984

cve-icon Vulnrichment

Updated: 2025-09-04T20:07:28.631Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-09-04T10:42:33.990

Modified: 2025-09-04T15:35:29.497

Link: CVE-2025-6984

cve-icon Redhat

Severity : Important

Publid Date: 2025-09-04T08:07:41Z

Links: CVE-2025-6984 - Bugzilla