¡¾Îó²îͨ¸æ¡¿LangChain ÐòÁл¯×¢ÈëÎó²îµ¼ÖÂÃô¸ÐÐÅϢй¶(CVE-2025-68664)

Ðû²¼Ê±¼ä 2025-12-25

Ò»¡¢Îó²î¸ÅÊö


Îó²îÃû³Æ

LangChain ÐòÁл¯×¢ÈëÎó²îµ¼ÖÂÃô¸ÐÐÅϢй¶

CVE   ID

CVE-2025-68664

Îó²îÀàÐÍ

·´ÐòÁл¯×¢Èë

·¢Ã÷ʱ¼ä

2025-12-25

Îó²îÆÀ·Ö

9.3

Îó²îÆ·¼¶

ÑÏÖØ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

²»ÐèÒª

PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ

δ·¢Ã÷


LangChainÊÇÒ»¸öÃæÏò´óÓïÑÔÄ£×Ó£¨LLM£©µÄÓ¦Óÿª·¢¿ò¼Ü£¬£¬ £¬£¬£¬ÌṩÁ´Ê½Å²Óá¢ÌáÐÑÄ£°å¡¢Ó°ÏóÖÎÀí¡¢¹¤¾ßÓëÊðÀíµÈÄÜÁ¦£¬£¬ £¬£¬£¬×ÊÖú¿ª·¢Õ߸ßЧ¹¹½¨¡¢±àÅźͰ²ÅÅ»ùÓÚLLMµÄÖØ´óÓ¦Ó㬣¬ £¬£¬£¬ÆÕ±éÓÃÓÚ¶Ô»°ÏµÍ³¡¢ÖªÊ¶¼ìË÷ÓëÖÇÄÜ×Ô¶¯»¯³¡¾°¡£¡£¡£


2025Äê12ÔÂ25ÈÕ£¬£¬ £¬£¬£¬ÄϹ¬NGÓéÀÖ¼¯ÍÅVSRC¼à²âµ½LangChainÐòÁл¯×¢ÈëÎó²î£¬£¬ £¬£¬£¬¸ÃÎó²îÔ´ÓÚdumps()Óëdumpd()º¯ÊýÔÚ´¦Öóͷ£×ÔÓÉ×Öµäʱδ׼ȷתÒå°üÀ¨¡°lc¡±Òªº¦×ÖµÄÓû§¿É¿ØÊý¾Ý£¬£¬ £¬£¬£¬µ¼ÖÂÆäÔÚload()»òloads()·´ÐòÁл¯Àú³ÌÖб»Îóʶ±ðΪÕýµ±µÄLangChain¹¤¾ß½á¹¹¡£¡£¡£¹¥»÷Õß¿Éͨ¹ýÔÚLLMÏìÓ¦¡¢metadata¡¢additional_kwargsµÈ¿É¿Ø×Ö¶ÎÖÐ×¢ÈëÌØÖÆÐòÁл¯½á¹¹£¬£¬ £¬£¬£¬ÊµÏÖÃôÇéÐ÷ÐαäÁ¿Ð¹Â¶£¬£¬ £¬£¬£¬»òÔÚÊÜÐÅÃüÃû¿Õ¼äÄÚʵÀý»¯¾ßÓи±×÷ÓõÄÀà¡£¡£¡£¸ÃÎó²îÓ°Ïì¶à¸öÄÚ²¿ÐòÁл¯Å²Óó¡¾°£¬£¬ £¬£¬£¬Ôھɰ汾ĬÈÏ¿ªÆôsecrets_from_envµÄÇéÐÎÏÂΣº¦ÓÈΪͻ³ö¡£¡£¡£


¶þ¡¢Ó°Ïì¹æÄ£


1.0.0 <= langchain < 1.2.5
langchain < 0.3.81


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


¹Ù·½ÒÑÐû²¼ÐÞ¸´²¹¶¡£¬£¬ £¬£¬£¬ÒÔÐÞ¸´¸ÃÎó²î¡£¡£¡£
langchain >= 1.2.5
langchain >= 0.3.81


ÏÂÔØÁ´½Ó£ºhttps://github.com/langchain-ai/langchain/releases/


3.2 ÔÝʱ²½·¥


ÔÝÎÞ¡£¡£¡£


3.3 ͨÓý¨Òé


? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬ £¬£¬£¬ïÔ̭ϵͳÎó²î£¬£¬ £¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£
ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬ £¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬ £¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬ £¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬ £¬£¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£¡£
ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬ £¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£
ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬ £¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬£¬ £¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£
ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£


3.4 ²Î¿¼Á´½Ó


https://nvd.nist.gov/vuln/detail/CVE-2025-68664/
https://github.com/langchain-ai/langchain/security/advisories/GHSA-c67j-w6g6-q2cm