langchain-ai v0.3.51 was discovered to contain an indirect prompt injection vulnerability in the GmailToolkit component. This vulnerability allows attackers to execute arbitrary code and compromise the application via a crafted email message. NOTE: this is disputed by the Supplier because the code-execution issue was introduced by user-written code that does not adhere to the LangChain security practices.
Metrics
Affected Vendors & Products
References
History
Sun, 03 Aug 2025 23:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | langchain-ai v0.3.51 was discovered to contain an indirect prompt injection vulnerability in the GmailToolkit component. This vulnerability allows attackers to execute arbitrary code and compromise the application via a crafted email message. | langchain-ai v0.3.51 was discovered to contain an indirect prompt injection vulnerability in the GmailToolkit component. This vulnerability allows attackers to execute arbitrary code and compromise the application via a crafted email message. NOTE: this is disputed by the Supplier because the code-execution issue was introduced by user-written code that does not adhere to the LangChain security practices. |
References |
|
Wed, 30 Jul 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Langchain
Langchain langchain Langchain-ai Langchain-ai langchain |
|
Vendors & Products |
Langchain
Langchain langchain Langchain-ai Langchain-ai langchain |
Wed, 30 Jul 2025 00:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | langchain-core: Langchain indirect propmpt injection | |
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Tue, 29 Jul 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-94 | |
Metrics |
cvssV3_1
|
Tue, 29 Jul 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | langchain-ai v0.3.51 was discovered to contain an indirect prompt injection vulnerability in the GmailToolkit component. This vulnerability allows attackers to execute arbitrary code and compromise the application via a crafted email message. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-07-29T00:00:00.000Z
Updated: 2025-08-03T23:20:43.149Z
Reserved: 2025-04-22T00:00:00.000Z
Link: CVE-2025-46059

Updated: 2025-07-29T14:55:47.444Z

Status : Awaiting Analysis
Published: 2025-07-29T15:15:35.003
Modified: 2025-08-04T00:15:29.423
Link: CVE-2025-46059
