{"id":"PYSEC-2026-1514","summary":"LangChain pickle deserialization of untrusted data","details":"A vulnerability in the `FAISS.deserialize_from_bytes` function of langchain-ai/langchain allows for pickle deserialization of untrusted data. This can lead to the execution of arbitrary commands via the `os.system` function. The issue affects versions prior to 0.2.4.","aliases":["CVE-2024-5998","GHSA-f2jm-rw3h-6phg","PYSEC-2024-323"],"modified":"2026-07-13T07:26:23.643495355Z","published":"2026-07-07T14:34:41.419579Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-5998"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/604dfe2d99246b0c09f047c604f0c63eafba31e7"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/77209f315efd13442ec51c67719ba37dfaa44511"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"},{"type":"WEB","url":"https://huntr.com/bounties/fa3a2753-57c3-4e08-a176-d7a3ffda28fe"},{"type":"PACKAGE","url":"https://pypi.org/project/langchain-community"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-f2jm-rw3h-6phg"}],"affected":[{"package":{"name":"langchain-community","ecosystem":"PyPI","purl":"pkg:pypi/langchain-community"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.2.4"}]}],"versions":["0.0.1","0.0.10","0.0.11","0.0.12","0.0.13","0.0.14","0.0.15","0.0.16","0.0.17","0.0.18","0.0.19","0.0.1rc1","0.0.1rc2","0.0.2","0.0.20","0.0.21","0.0.22","0.0.23","0.0.24","0.0.25","0.0.26","0.0.27","0.0.28","0.0.29","0.0.3","0.0.30","0.0.31","0.0.32","0.0.33","0.0.34","0.0.35","0.0.36","0.0.37","0.0.38","0.0.4","0.0.5","0.0.6","0.0.7","0.0.8","0.0.9","0.2.0","0.2.0rc1","0.2.1","0.2.2","0.2.3"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/langchain-community/PYSEC-2026-1514.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:P/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"}]}