{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/langchain-nvidia-ai-endpoints--1.4.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:langchain:langchain-nvidia-ai-endpoints:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":5.3,"id":"CVE-2024-34812"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["langchain-nvidia-ai-endpoints (\u003c 1.4.2)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","local-file-inclusion","python","supply-chain"],"_cs_type":"advisory","_cs_vendors":["LangChain"],"content_html":"\u003cp\u003eThe \u003ccode\u003elangchain-nvidia-ai-endpoints\u003c/code\u003e Python package, specifically versions 1.4.1 and earlier, contains a local file disclosure vulnerability. The issue arises from the package's handling of Vision Language Model (VLM) image inputs, where the library fails to adequately sanitize or restrict image paths provided to the \u003ccode\u003eChatNVIDIA\u003c/code\u003e or VLM reranking APIs.\u003c/p\u003e\n\u003cp\u003eIf an application utilizing this library allows untrusted user input to influence the image source parameter, an attacker can supply local filesystem paths. When the library processes these requests, it treats the provided path as a file to be read by the application process. The contents of these files are then included in the payload sent to the configured NVIDIA/NIM model backend. This allows attackers to exfiltrate arbitrary files that the application process has permissions to read, such as configuration files, local credentials, or source code. The vulnerability was addressed in version 1.4.2, which strictly filters input types to only permit remote URLs, base64-encoded data URIs, and authorized asset identifiers.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eApplications built with \u003ccode\u003elangchain-nvidia-ai-endpoints\u003c/code\u003e that process untrusted image inputs are at risk of arbitrary file disclosure. If exploited, an attacker can gain unauthorized access to sensitive local files, which may lead to further exploitation, credential theft, or exposure of internal infrastructure details. The potential impact depends on the filesystem permissions assigned to the service account running the application process.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade \u003ccode\u003elangchain-nvidia-ai-endpoints\u003c/code\u003e to version 1.4.2 or later immediately.\u003c/li\u003e\n\u003cli\u003eIf patching is delayed, implement strict server-side validation to reject any user-supplied image input that resembles a local filesystem path (e.g., paths starting with \u003ccode\u003e/\u003c/code\u003e, \u003ccode\u003eC:\\\u003c/code\u003e, or relative path traversal sequences like \u003ccode\u003e../\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eEnforce the principle of least privilege for the application process; ensure the service account running the application has read access restricted only to the files and directories strictly necessary for its operation.\u003c/li\u003e\n\u003cli\u003eReview application logs for anomalous requests to the \u003ccode\u003eChatNVIDIA\u003c/code\u003e or reranking endpoints that contain suspicious local path string patterns in image parameters.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-24T20:06:01Z","date_published":"2026-09-24T20:06:01Z","id":"https://feed.craftedsignal.io/briefs/2026-09-langchain-nvidia-ai-endpoints-lfi/","summary":"The langchain-nvidia-ai-endpoints library versions prior to 1.4.2 are vulnerable to local file disclosure when attacker-controlled image inputs are passed to ChatNVIDIA or VLM reranking APIs, leading to unauthorized file reading and exfiltration to remote endpoints.","title":"Local File Disclosure in langchain-nvidia-ai-endpoints","url":"https://feed.craftedsignal.io/briefs/2026-09-langchain-nvidia-ai-endpoints-lfi/"}],"language":"en","title":"CraftedSignal Threat Feed - Langchain-Nvidia-Ai-Endpoints (\u003c 1.4.2)","version":"https://jsonfeed.org/version/1.1"}