CVE-2025-46059: Code Injection
langchain-ai v0.3.51 was discovered to contain an indirect prompt injection vulnerability in the GmailToolkit component. This vulnerability allows attackers to execute arbitrary code and compromise the application via a crafted email message. NOTE: this is disputed by the Supplier because the code-execution issue was introduced by user-written code that does not adhere to the LangChain security practices.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46059?
CVE-2025-46059 is classified as a critical vulnerability due to its potential to allow arbitrary code execution.
How do I fix CVE-2025-46059?
To fix CVE-2025-46059, update to the latest version of langchain-ai that addresses this vulnerability.
What is the main impact of CVE-2025-46059?
The main impact of CVE-2025-46059 is that attackers can compromise the application by sending a crafted email message.
Which component of langchain-ai is affected by CVE-2025-46059?
CVE-2025-46059 affects the GmailToolkit component of langchain-ai.
Is CVE-2025-46059 an injection vulnerability?
Yes, CVE-2025-46059 is an indirect prompt injection vulnerability.