¡¾Îó²îͨ¸æ¡¿LangChain ÐòÁл¯×¢ÈëÎó²îµ¼ÖÂÃô¸ÐÐÅϢй¶(CVE-2025-68664)

Ðû²¼Ê±¼ä 2025-12-25

Ò»¡¢Îó²î¸ÅÊö


Îó²îÃû³Æ

LangChain ÐòÁл¯×¢ÈëÎó²îµ¼ÖÂÃô¸ÐÐÅϢй¶

CVE   ID

CVE-2025-68664

Îó²îÀàÐÍ

·´ÐòÁл¯×¢Èë

·¢Ã÷ʱ¼ä

2025-12-25

Îó²îÆÀ·Ö

9.3

Îó²îÆ·¼¶

ÑÏÖØ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

²»ÐèÒª

PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ

δ·¢Ã÷


LangChainÊÇÒ»¸öÃæÏò´óÓïÑÔÄ£×Ó£¨LLM£©µÄÓ¦Óÿª·¢¿ò¼Ü£¬ÌṩÁ´Ê½Å²Óá¢ÌáÐÑÄ£°å¡¢Ó°ÏóÖÎÀí¡¢¹¤¾ßÓëÊðÀíµÈÄÜÁ¦£¬×ÊÖú¿ª·¢Õ߸ßЧ¹¹½¨¡¢±àÅźͰ²ÅÅ»ùÓÚLLMµÄÖØ´óÓ¦Óã¬ÆÕ±éÓÃÓÚ¶Ô»°ÏµÍ³¡¢ÖªÊ¶¼ìË÷ÓëÖÇÄÜ×Ô¶¯»¯³¡¾°¡£


2025Äê12ÔÂ25ÈÕ£¬×ðÁú¿­Ê±¼¯ÍÅVSRC¼à²âµ½LangChainÐòÁл¯×¢ÈëÎó²î£¬¸ÃÎó²îÔ´ÓÚdumps()Óëdumpd()º¯ÊýÔÚ´¦Öóͷ£×ÔÓÉ×Öµäʱδ׼ȷתÒå°üÀ¨¡°lc¡±Òªº¦×ÖµÄÓû§¿É¿ØÊý¾Ý£¬µ¼ÖÂÆäÔÚload()»òloads()·´ÐòÁл¯Àú³ÌÖб»Îóʶ±ðΪÕýµ±µÄLangChain¹¤¾ß½á¹¹¡£¹¥»÷Õß¿Éͨ¹ýÔÚLLMÏìÓ¦¡¢metadata¡¢additional_kwargsµÈ¿É¿Ø×Ö¶ÎÖÐ×¢ÈëÌØÖÆÐòÁл¯½á¹¹£¬ÊµÏÖÃôÇéÐ÷ÐαäÁ¿Ð¹Â¶£¬»òÔÚÊÜÐÅÃüÃû¿Õ¼äÄÚʵÀý»¯¾ßÓи±×÷ÓõÄÀà¡£¸ÃÎó²îÓ°Ïì¶à¸öÄÚ²¿ÐòÁл¯Å²Óó¡¾°£¬Ôھɰ汾ĬÈÏ¿ªÆôsecrets_from_envµÄÇéÐÎÏÂΣº¦ÓÈΪͻ³ö¡£


¶þ¡¢Ó°Ïì¹æÄ£


1.0.0 <= langchain < 1.2.5
langchain < 0.3.81


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


¹Ù·½ÒÑÐû²¼ÐÞ¸´²¹¶¡£¬ÒÔÐÞ¸´¸ÃÎó²î¡£
langchain >= 1.2.5
langchain >= 0.3.81


ÏÂÔØÁ´½Ó£ºhttps://github.com/langchain-ai/langchain/releases/


3.2 ÔÝʱ²½·¥


ÔÝÎÞ¡£


3.3 ͨÓý¨Òé


? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬ïÔ̭ϵͳÎó²î£¬ÌáÉý·þÎñÆ÷µÄÇå¾²ÐÔ¡£
ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬Ð޸ķÀ»ðǽսÂÔ£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬ïÔÌ­½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬ïÔÌ­¹¥»÷Ãæ¡£
ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£
ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£
ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£


3.4 ²Î¿¼Á´½Ó


https://nvd.nist.gov/vuln/detail/CVE-2025-68664/
https://github.com/langchain-ai/langchain/security/advisories/GHSA-c67j-w6g6-q2cm