
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-40087 is an incomplete f-string prompt-template validation vulnerability in LangChain's langchain-core package that allows network-accessible attackers to extract sensitive data through crafted template injection. It affects langchain-core versions prior to 0.3.84 (for the 0.x series) and versions 1.0.0 through 1.2.27 (for the 1.x series). The vulnerability was published on April 9, 2026, with patches released the same day. It carries a CVSS v3.1 base score of 5.3 (Medium) (GitHub Advisory, Feedly).
The root cause is improper neutralization of special elements used in a template engine (CWE-1336), manifesting in two distinct gaps in LangChain's f-string validation logic. First, DictPromptTemplate and ImagePromptTemplate accepted f-string templates containing attribute access (.) or indexing ([]) expressions — such as "{message.additional_kwargs[secret]}" or "https://example.com/{image.__class__.__name__}.png" — and evaluated them at formatting time without the same safety checks applied to PromptTemplate. Second, the validation logic parsed only top-level field names, so nested replacement fields embedded inside format specifiers (e.g., "{name:{name.__class__.__name__}}") bypassed validation entirely, since the nested expression appears in the format specifier position rather than the field name position, yet Python's str.format() still resolves it at runtime. Exploitation requires an attacker to control the template string itself (not merely template variable values), and impact scales with the richness of Python objects passed into formatting (GitHub Advisory, Patch PR #36612).
Successful exploitation can expose internal fields, nested data, or sensitive attributes of Python objects passed into template formatting — potentially leaking information into prompt output, model context, or application logs. The confidentiality impact is rated Low by CVSS, as meaningful data exposure requires the attacker to control the template structure and the application to pass richer internal Python objects (rather than simple strings or numbers) into formatting. There is no integrity or availability impact. IBM products incorporating LangChain — including Cloud Pak for AIOps, Cloud Pak for Business Automation, Business Automation Workflow, and watsonx Orchestrate — are also affected as downstream consumers (GitHub Advisory, IBM Advisory).
No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time. The vulnerability is network-accessible, requires no authentication or user interaction, and has low attack complexity, but exploitation is constrained by the requirement that the attacker control the template string itself rather than just variable values. The EPSS score is approximately 0.036%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly, GitHub Advisory).
langchain-core < 0.3.84 or 1.0.0–1.2.27 that accepts user-supplied f-string template strings (not just variable values) and uses DictPromptTemplate, ImagePromptTemplate, or f-string templates with nested format specifiers."{message.additional_kwargs[secret]}" or "https://example.com/{image.__class__.__name__}.png" targeting DictPromptTemplate or ImagePromptTemplate, which lack the attribute-access validation present in PromptTemplate."{name:{name.__class__.__name__}}" where the nested replacement field in the format specifier bypasses top-level field name validation but is still resolved by Python's formatter at runtime..format() method with a rich Python object (e.g., a LangChain message object) as the variable value, so that attribute traversal or indexing expressions are evaluated.. or [] in variable names (e.g., {obj.attr}, {obj[key]}) or nested replacement fields in format specifiers (e.g., {name:{name.__class__.__name__}}) in application configuration, serialized payloads, or user input.DictPromptTemplate or ImagePromptTemplate with template values containing attribute access syntax, submitted via API endpoints or configuration interfaces.ValueError exceptions referencing "Variable names cannot contain attribute access" or "Nested replacement fields are not allowed" in applications running patched versions, indicating attempted exploitation (GitHub Advisory).Upgrade langchain-core to version 0.3.84 (for the 0.x series) or 1.2.28 (for the 1.x series), which apply consistent f-string safety validation to DictPromptTemplate and ImagePromptTemplate and reject nested replacement fields in format specifiers. As a workaround prior to patching, ensure that applications do not accept untrusted user-supplied template strings — restricting users to providing only variable values (not template structure) eliminates the attack surface entirely. Additionally, review any application code that passes rich Python objects into template formatting and consider restricting inputs to simple types (strings, numbers) until patching is complete (GitHub Advisory, IBM Advisory).
The fix was authored and merged by LangChain core maintainer Eugene Yurtsev (eyurtsev) on April 8, 2026, with the security advisory published the following day. IBM issued multiple advisories in late April and May 2026 acknowledging the impact on Cloud Pak for AIOps, Cloud Pak for Business Automation, Business Automation Workflow, and watsonx Orchestrate, reflecting the broad downstream reach of the vulnerability in enterprise AI platforms (IBM Advisory, IBM CP4BA Advisory). No significant independent researcher commentary or social media discussion has been identified beyond standard CVE tracking and vendor bulletins.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."