The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The affected version is 0.3.63. The vulnerability arises from the use of etree.iterparse() without disabling external entity references, which can lead to sensitive information disclosure. An attacker could exploit this by crafting a malicious XML payload that references local files, potentially exposing sensitive data such as /etc/passwd.
History

Thu, 04 Sep 2025 08:15:00 +0000

Type Values Removed Values Added
Description The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The affected version is 0.3.63. The vulnerability arises from the use of etree.iterparse() without disabling external entity references, which can lead to sensitive information disclosure. An attacker could exploit this by crafting a malicious XML payload that references local files, potentially exposing sensitive data such as /etc/passwd.
Title Sensitive Information Disclosure Due to Insecure XML Parsing in langchain-ai/langchain
Weaknesses CWE-200
References
Metrics cvssV3_0

{'score': 7.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published:

Updated: 2025-09-04T08:07:41.996Z

Reserved: 2025-07-01T20:19:39.922Z

Link: CVE-2025-6984

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-09-04T10:42:33.990

Modified: 2025-09-04T10:42:33.990

Link: CVE-2025-6984

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.