The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The affected version is 0.3.63. The vulnerability arises from the use of etree.iterparse() without disabling external entity references, which can lead to sensitive information disclosure. An attacker could exploit this by crafting a malicious XML payload that references local files, potentially exposing sensitive data such as /etc/passwd.
Metrics
Affected Vendors & Products
References
History
Fri, 05 Sep 2025 00:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Thu, 04 Sep 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 04 Sep 2025 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Langchain-ai
Langchain-ai langchain |
|
Vendors & Products |
Langchain-ai
Langchain-ai langchain |
Thu, 04 Sep 2025 08:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The affected version is 0.3.63. The vulnerability arises from the use of etree.iterparse() without disabling external entity references, which can lead to sensitive information disclosure. An attacker could exploit this by crafting a malicious XML payload that references local files, potentially exposing sensitive data such as /etc/passwd. | |
Title | Sensitive Information Disclosure Due to Insecure XML Parsing in langchain-ai/langchain | |
Weaknesses | CWE-200 | |
References |
| |
Metrics |
cvssV3_0
|

Status: PUBLISHED
Assigner: @huntr_ai
Published: 2025-09-04T08:07:41.996Z
Updated: 2025-09-04T20:07:31.531Z
Reserved: 2025-07-01T20:19:39.922Z
Link: CVE-2025-6984

Updated: 2025-09-04T20:07:28.631Z

Status : Awaiting Analysis
Published: 2025-09-04T10:42:33.990
Modified: 2025-09-04T15:35:29.497
Link: CVE-2025-6984
