Threats Tagged 'cve-2025-68664'
View all threats tagged with 'cve-2025-68664'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2025-68664'
Click on any threat for detailed analysis and mitigation recommendations
Red Hat OpenShift Lightspeed is a generative AI-based virtual assistant integrated into the OpenShift console. It can answer questions related to OpenShift and layered offerings. Security Fix(es): langchain-core: LangChain: Arbitrary code execution via serialization injection (CVE-2025-68664) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.` Join the discussion | GCVE Database | 01/30/2026, 18:51:47 UTC Added: 05/26/2026, 20:58:48 UTC |
0 Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. Join the discussion | GCVE Database | 01/08/2026, 19:41:55 UTC Added: 05/26/2026, 20:58:48 UTC |
CVE-2025-68664 is a critical deserialization vulnerability in the LangChain framework versions prior to 0.3.81 and 1.2.5. The vulnerability arises because LangChain's dumps() and dumpd() serialization functions do not properly escape dictionaries containing the 'lc' key, which is internally used to mark serialized objects. Malicious actors can craft user-controlled data with this key to trigger unsafe deserialization, leading to potential remote code execution or unauthorized data manipulation. The vulnerability has a CVSS score of 9.3, indicating high severity with network attack vector, no privileges or user interaction required, and a scope change. European organizations using vulnerable LangChain versions in AI or agent-based applications face risks of confidentiality breaches and integrity violations. Join the discussion | CVE Database V5 | 12/23/2025, 22:47:44 UTC Added: 12/23/2025, 22:56:49 UTC |
Showing 1 to 3 of 3 results