Update dependency langchain-community to v0.3.27 [SECURITY] #81

Merged
renovate[bot] merged 1 commit from renovate/pypi-langchain-community-vulnerability into main 2026-06-11 18:47:38 +00:00
renovate[bot] commented 2026-04-02 17:22:23 +00:00 (Migrated from github.com)

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
langchain-community (changelog) ==0.3.23 → ==0.3.27 age adoption passing confidence

Langchain Community Vulnerable to XML External Entity (XXE) Attacks

CVE-2025-6984 / GHSA-pc6w-59fv-rh23

More information

Details

The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The vulnerability arises from the use of etree.iterparse() without disabling external entity references, which can lead to sensitive information disclosure. An attacker could exploit this by crafting a malicious XML payload that references local files, potentially exposing sensitive data such as /etc/passwd. This issue has been fixed in 0.3.27 of langchain-community.

Severity

  • CVSS Score: 7.5 / 10 (High)
  • Vector String: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • ""
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Adoption](https://docs.renovatebot.com/merge-confidence/) | [Passing](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---|---|---| | [langchain-community](https://redirect.github.com/langchain-ai/langchain-community) ([changelog](https://redirect.github.com/langchain-ai/langchain/releases?q=tag%3A%22langchain-community%3D%3D0%22&expanded=true)) | `==0.3.23` → `==0.3.27` | ![age](https://developer.mend.io/api/mc/badges/age/pypi/langchain-community/0.3.27?slim=true) | ![adoption](https://developer.mend.io/api/mc/badges/adoption/pypi/langchain-community/0.3.27?slim=true) | ![passing](https://developer.mend.io/api/mc/badges/compatibility/pypi/langchain-community/0.3.23/0.3.27?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/pypi/langchain-community/0.3.23/0.3.27?slim=true) | --- ### Langchain Community Vulnerable to XML External Entity (XXE) Attacks [CVE-2025-6984](https://nvd.nist.gov/vuln/detail/CVE-2025-6984) / [GHSA-pc6w-59fv-rh23](https://redirect.github.com/advisories/GHSA-pc6w-59fv-rh23) <details> <summary>More information</summary> #### Details The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The vulnerability arises from the use of etree.iterparse() without disabling external entity references, which can lead to sensitive information disclosure. An attacker could exploit this by crafting a malicious XML payload that references local files, potentially exposing sensitive data such as /etc/passwd. This issue has been fixed in 0.3.27 of langchain-community. #### Severity - CVSS Score: 7.5 / 10 (High) - Vector String: `CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N` #### References - [https://nvd.nist.gov/vuln/detail/CVE-2025-6984](https://nvd.nist.gov/vuln/detail/CVE-2025-6984) - [https://huntr.com/bounties/a6b521cf-258c-41c0-9edb-d8ef976abb2a](https://huntr.com/bounties/a6b521cf-258c-41c0-9edb-d8ef976abb2a) - [https://github.com/langchain-ai/langchain-community/commit/e842452108089524e22c3a2ced851c021884556f](https://redirect.github.com/langchain-ai/langchain-community/commit/e842452108089524e22c3a2ced851c021884556f) - [https://github.com/langchain-ai/langchain/blob/d79b5813a0b3b243c612b77013768995e46c4337/libs/langchain/langchain/document_loaders/evernote.py#L1-L23](https://redirect.github.com/langchain-ai/langchain/blob/d79b5813a0b3b243c612b77013768995e46c4337/libs/langchain/langchain/document_loaders/evernote.py#L1-L23) - [https://github.com/advisories/GHSA-pc6w-59fv-rh23](https://redirect.github.com/advisories/GHSA-pc6w-59fv-rh23) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-pc6w-59fv-rh23) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - "" - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/sarumaj/rag-agent). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMDIuMTEiLCJ1cGRhdGVkSW5WZXIiOiI0My4xMzguMSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->
Sign in to join this conversation.
No description provided.