OVERVIEW CVE-2026-40087 affects LangChain, a popular framework for building AI agents and large language model-powered applications. The vulnerability stems from incomplete validation of f-string prompt templates in multiple template classes. Specifically, DictPromptTemplate and ImagePromptTemplate fail to enforce the same attribute-access restrictions as the base PromptTemplate class, and the validation logic does not properly detect nested replacement fields within format specifiers. This allows attackers to inject attribute access or indexing expressions that are evaluated during template formatting. The vulnerability impacts LangChain versions prior to 0.3.84 and 1.2.28. SEVERITY The vulnerability carries a CVSS 3.1 score of 5.3 (Medium), with a network-based attack vector requiring no special privileges or user interaction. The attack complexity is low, meaning exploitation requires minimal effort. The impact is limited to confidentiality, as the vulnerability enables information disclosure through unauthorized attribute access, while integrity and availability remain unaffected. The EPSS score of 0.0005 indicates this vulnerability has a lower probability of exploitation compared to the broader CVE landscape, though the 32.0/100 FAUCET risk score suggests some operational concern. EXPLOITATION STATUS There is no current evidence of active exploitation. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog and is marked as inactive on threat intelligence platforms. No publicly available exploit code has been disclosed, and community attention remains minimal, suggesting responsible disclosure practices are being followed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.3.84CPE matchmatch criteria | cpe:2.3:a:langchain:langchain_core:*:*:*:*:*:python:*:* | ||
>= 1.0.0, < 1.2.28CPE matchmatch criteria | cpe:2.3:a:langchain:langchain_core:*:*:*:*:*:python:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.