A high-severity security vulnerability (CVE-2026-34070, CVSS 7.5) has been patched in langchain-core, the foundational library underpinning the LangChain ecosystem used by enterprise teams to build Large Language Model (LLM) orchestration pipelines and Retrieval-Augmented Generation (RAG) applications. The flaw enables remote attackers processing untrusted prompt templates to read arbitrary files from the underlying operating system.
The Mechanics of Prompt Ingestion in AI Agent Pipelines
In modern enterprise AI systems, prompt templates are frequently serialized as JSON or YAML files, allowing non-technical domain experts to customize agent personas, few-shot examples, and guardrail instructions. Applications often load these templates dynamically from external repositories, user uploads, or database records using LangChain's load_prompt API.
However, when load_prompt evaluated template configuration files containing nested _type: prompt schemas, it parsed the template_path key without confining the path to a designated root directory.
Root Cause Breakdown: Unsafe Path Resolution (CWE-22)
The defect is cataloged as CWE-22: Improper Limitation of a Pathname to a Restricted Directory. Because the loader invoked standard Python open() calls directly on the user-supplied path string, an attacker supplying relative traversal tokens (../../../../etc/passwd) or absolute system paths could force the loader to read sensitive system configuration files into the active prompt context:
# Adversarial prompt configuration payload triggering CVE-2026-34070
_type: prompt
input_variables: ["user_query"]
template_path: "../../../../../etc/shadow"
When the application serialized the prompt into model input, the contents of the target file were incorporated into the system prompt or returned in debugging telemetry, resulting in unauthorized information disclosure.
Remediation & Defense Framework
- Upgrade Dependency: Update to langchain-core v1.2.22 or higher across all virtual environments.
- Strict Path Validation: The updated release introduces mandatory security checks that reject directory traversal sequences by default unless
allow_dangerous_paths=Trueis explicitly passed. - Sandbox RAG Workflows: Execute AI prompt loading routines within ephemeral container sandboxes stripped of read permissions to host credentials and secrets.



