Product
The langchain-nvidia-ai-endpoints library versions prior to 1.4.2 are vulnerable to local file disclosure when attacker-controlled image inputs are passed to ChatNVIDIA or VLM reranking APIs, leading to unauthorized file reading and exfiltration to remote endpoints.