A critical prompt injection vulnerability (CVE-2025-12345) has been discovered in LangChain versions prior to 0.2.0, affecting chain-of-thought and agent implementations.
CVE-2025-12345 affects LangChain < 0.2.0 with CVSS 9.1
Dec 20, 2025Prompt injection allows arbitrary code execution in agent mode
Dec 20, 2025Immediate upgrade to LangChain 0.2.1+ strongly recommended
Dec 21, 2025