The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The affected version is 0.3.63. The vulnerability arises from the use of etree.iterparse() without disabling external entity references, which can lead to sensitive information disclosure. An attacker could exploit this by crafting a malicious XML payload that references local files, potentially exposing sensitive data such as /etc/passwd.
                
            Metrics
Affected Vendors & Products
References
        History
                    Fri, 05 Sep 2025 00:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References |  | |
| Metrics | threat_severity 
 | threat_severity 
 | 
Thu, 04 Sep 2025 20:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Thu, 04 Sep 2025 13:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Langchain-ai Langchain-ai langchain | |
| Vendors & Products | Langchain-ai Langchain-ai langchain | 
Thu, 04 Sep 2025 08:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The affected version is 0.3.63. The vulnerability arises from the use of etree.iterparse() without disabling external entity references, which can lead to sensitive information disclosure. An attacker could exploit this by crafting a malicious XML payload that references local files, potentially exposing sensitive data such as /etc/passwd. | |
| Title | Sensitive Information Disclosure Due to Insecure XML Parsing in langchain-ai/langchain | |
| Weaknesses | CWE-200 | |
| References |  | |
| Metrics | cvssV3_0 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: @huntr_ai
Published: 2025-09-04T08:07:41.996Z
Updated: 2025-09-04T20:07:31.531Z
Reserved: 2025-07-01T20:19:39.922Z
Link: CVE-2025-6984
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-09-04T20:07:28.631Z
 NVD
                        NVD
                    Status : Awaiting Analysis
Published: 2025-09-04T10:42:33.990
Modified: 2025-09-04T15:35:29.497
Link: CVE-2025-6984
 Redhat
                        Redhat
                     ReportizFlow
ReportizFlow