Echo: langchain-core: security update to 0.1.53

medium Tenable Self-Hosted Container Security Plugin ID 463846

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- A vulnerability in langchain-core versions >=0.1.17,<0.1.53, >=0.2.0,<0.2.43, and >=0.3.0,<0.3.15 allows
unauthorized users to read arbitrary files from the host file system. The issue arises from the ability to
create langchain_core.prompts.ImagePromptTemplate's (and by extension
langchain_core.prompts.ChatPromptTemplate's) with input variables that can read any user-specified path
from the server file system. If the outputs of these prompt templates are exposed to the user, either
directly or through downstream model outputs, it can lead to the exposure of sensitive information.
(CVE-2024-10940)

Solution

Update the langchain-core library and its related packages to version 0.1.53 or later.

See Also

https://advisory.echohq.com/cve/CVE-2024-10940

Plugin Details

Severity: Medium

ID: 463846

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/3/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2024-10940

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.6

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 7/1/2026

Vulnerability Publication Date: 3/20/2025

Reference Information

CVE: CVE-2024-10940