Server Side Template Injection Vulnerability in Langchaingo by TMC
CVE-2025-9556

9.8CRITICAL

Key Information:

Vendor
CVE Published:
12 September 2025

What is CVE-2025-9556?

A server side template injection vulnerability in Langchaingo allows attackers to exploit the jinja2 syntax during prompt parsing. This is facilitated by the gonja library, specifically version 1.5.3, which permits the use of include and extend syntax to access files on the server. Through crafted inputs, attackers could manipulate prompts to read sensitive files such as 'etc/passwd', potentially exposing critical system information.

Affected Version(s)

Langchaingo 0.1.14

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.