The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The affected version is 0.3.63. The vulnerability arises from the use of etree.iterparse() without disabling external entity references, which can lead to sensitive information disclosure. An attacker could exploit this by crafting a malicious XML payload that references local files, potentially exposing sensitive data such as /etc/passwd.
Metrics
Affected Vendors & Products
References
History
Thu, 04 Sep 2025 08:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The affected version is 0.3.63. The vulnerability arises from the use of etree.iterparse() without disabling external entity references, which can lead to sensitive information disclosure. An attacker could exploit this by crafting a malicious XML payload that references local files, potentially exposing sensitive data such as /etc/passwd. | |
Title | Sensitive Information Disclosure Due to Insecure XML Parsing in langchain-ai/langchain | |
Weaknesses | CWE-200 | |
References |
| |
Metrics |
cvssV3_0
|

Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2025-09-04T08:07:41.996Z
Reserved: 2025-07-01T20:19:39.922Z
Link: CVE-2025-6984

No data.

Status : Received
Published: 2025-09-04T10:42:33.990
Modified: 2025-09-04T10:42:33.990
Link: CVE-2025-6984

No data.

No data.