Deserialization Flaw in LangChain4j Agentic Component Impacting Multiple Releases
CVE-2026-97869
Key Information:
- Vendor
LangChain4j
- Status
- Vendor
- CVE Published:
- 25 September 2026
Badges
What is CVE-2026-97869?
A deserialization flaw in the LangChain4j-agentic component impacts multiple pre-release versions, allowing remote exploitation if AgenticScope persistence is enabled. This issue was identified in the AgenticScopeSerializer.fromJson method and poses a risk where an attacker with write access to the persistence store could trigger arbitrary code execution. Users are recommended to upgrade to the latest patched versions to mitigate potential exploitation risks.
Affected Version(s)
langchain4j 1.5.3-beta10
langchain4j 1.11.10-beta18
langchain4j 1.18.1-beta27
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
