Skip to content

Conversation

@renovate-bot
Copy link
Contributor

This PR contains the following updates:

Package Change Age Confidence
langchain-community (changelog) ==0.2.19 -> ==0.3.27 age confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.

GitHub Vulnerability Alerts

CVE-2025-6984

The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The vulnerability arises from the use of etree.iterparse() without disabling external entity references, which can lead to sensitive information disclosure. An attacker could exploit this by crafting a malicious XML payload that references local files, potentially exposing sensitive data such as /etc/passwd. This issue has been fixed in 0.3.27 of langchain-community.


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@forking-renovate forking-renovate bot added the lang: python Issues specific to Python. label Sep 5, 2025
@renovate-bot renovate-bot requested a review from a team as a code owner September 5, 2025 15:43
@renovate-bot renovate-bot added lang: python Issues specific to Python. type:security labels Sep 5, 2025
@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch 2 times, most recently from 31a49a7 to ab6a32b Compare September 15, 2025 15:46
@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch 5 times, most recently from 9322ce3 to 873342c Compare September 23, 2025 19:27
@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch 5 times, most recently from 56dc1f7 to 8e9bc86 Compare October 1, 2025 05:31
@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch 7 times, most recently from 144d892 to 1265a68 Compare October 9, 2025 02:32
@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch 5 times, most recently from 4c83c99 to 3bdd5bb Compare October 15, 2025 21:24
@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch 3 times, most recently from 692ba08 to 5ba30e6 Compare October 28, 2025 13:21
@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch 3 times, most recently from 870bed4 to 20db323 Compare November 5, 2025 19:54
@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch 2 times, most recently from d7db507 to eaa3346 Compare November 30, 2025 16:12
@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch 2 times, most recently from c9f032b to 67767c9 Compare December 1, 2025 07:12
@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 67767c9 to ee738fe Compare December 2, 2025 03:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

lang: python Issues specific to Python. type:security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant