TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Exploit-DB

[webapps] LangChain Core 1.2.4 - SSTI/RCE

2026-04-29 · Read original ↗

ATT&CK techniques detected

2 predictions
T1059.007JavaScript
74%
"} # serialize ( dumps does not escape ' lc ' key ) serialized = dumps ( payload ) # deserialize - instantiates the malicious prompttemplate deserialized = load ( serialized, secrets _ from _ env = true ) # extract and invoke the malicious prompt → triggers ssti → rce malicious = …"
T1059.006Python
32%
"[ webapps ] langchain core 1. 2. 4 - ssti / rce # exploit title : langchain core - ssti / rce # date : 2025 - 12 - 29 # exploit author : mohammed idrees banyamer # author country : jordan # contact : @ banyamer _ security ( instagram ) # github : https : / / github. com / mbanyam…"

Summary

LangChain Core 1.2.4 - SSTI/RCE