CVE-2025-6984
Python vulnerability analysis and mitigation

Overview

The langchain-ai/langchain project, specifically the EverNoteLoader component version 0.3.63, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. This vulnerability was disclosed on September 4, 2025 (NVD).

Technical details

The vulnerability arises from the use of etree.iterparse() without disabling external entity references in the EverNoteLoader component. The severity of this vulnerability has been rated as HIGH with a CVSS v3.0 base score of 7.5 (Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). The vulnerability has been classified under CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) (NVD, Huntr).

Impact

The vulnerability can lead to sensitive information disclosure. An attacker could potentially exploit this by crafting a malicious XML payload that references local files, potentially exposing sensitive data such as /etc/passwd (NVD).

Additional resources


SourceThis report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-23949HIGH8.6
  • PythonPython
  • jaraco.context
NoYesJan 20, 2026
CVE-2026-22219HIGH8.3
  • PythonPython
  • chainlit
NoYesJan 20, 2026
CVE-2026-23842HIGH7.5
  • PythonPython
  • chatterbot
NoYesJan 19, 2026
CVE-2026-23877MEDIUM5.3
  • PythonPython
  • swingmusic
NoYesJan 19, 2026
CVE-2026-23833LOW1.7
  • PythonPython
  • esphome
NoYesJan 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management