216.73.217.172

CVE-2025-6984

· Published 04/09/2025 10:42 · Modified 04/09/2025 15:35

Labels: CVE-2025-6984 2025-09-04CVE-2025-6984CWE-200[email protected]

Essential information

Published
04/09/2025 10:42
Modified
04/09/2025 15:35
Author
Creator
CVSS
7.5 HIGH (v3.0)
CISA KEV
No
CWE
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS metrics

Description

The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The affected version is 0.3.63. The vulnerability arises from the use of etree.iterparse() without disabling external entity references, which can lead to sensitive information disclosure. An attacker could exploit this by crafting a malicious XML payload that references local files, potentially exposing sensitive data such as /etc/passwd.

NVD status

Status
Awaiting Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
langchain-ai / langchain cpe:2.3:a:langchain-ai:langchain:0.3.63:*:*:*:*:*:*:*

References