Thank you for helping us keep LangChain secure. LangChain's open-source projects are frameworks for building applications powered by large language models, relied on by developers and companies around the world. Before submitting, please review the full policy, including scope and exclusions, and send detailed, reproducible reports following Intigriti's submission guidelines. Rewards and report acceptance are at LangChain's discretion, based on a finding's demonstrated impact and severity.
This is a responsible disclosure program without bounties.
By participating in this program, you agree to:
- Respect the Community Code of Conduct
- Respect the Intigriti Terms and Conditions
- Respect the scope of the program
- Not discuss or disclose vulnerability information without prior written consent (including PoC's on YouTube and Vimeo)
Validation times
We will validate all submissions within the below timelines, once your submission has been verified by Intigriti.
| Vulnerability Severity | Time to validate |
|---|---|
| Exceptional | 2 Working days |
| Critical | 2 Working days |
| High | 5 Working days |
| Medium | 15 Working days |
| Low | 15 Working days |
Introduction
LangChain deeply values the security community's efforts to find vulnerabilities in our open-source projects. This program covers our open-source projects developers use to build applications powered by large language models.
What we're looking for
We're most interested in findings that reflect a realistic attack scenario with genuine, demonstrable impact. Our key focus areas are:
- Code vulnerabilities that affect a project's default behavior and the configurations developers commonly use.
- Supply chain attacks, such as dependency confusion, malicious package injection, or compromise of the build and release pipeline.
- Leaked or exposed secrets and credentials, such as API keys or tokens committed to a repository.
To keep our focus where it has the most impact, please prioritize issues that could realistically affect a real deployment; findings that only surface under unusual or deliberately insecure setups generally fall outside this program.
Our documentation at https://docs.langchain.com/ covers how to set up and use LangChain's open-source frameworks.
General
- Theoretical security issues with no realistic exploit scenario(s) or attack surfaces, or issues that would require complex end user interactions to be exploited.
- In case that a reported vulnerability was already known to the company from their own tests, it will be flagged as a duplicate.
- Reports generated primarily by AI or automated tools without manual validation and a working proof of concept.
- Spam, social engineering and physical intrusion.
- DoS/DDoS attacks or brute force attacks.
- Attacks requiring physical access to a victim's computer/device, man in the middle or compromised user accounts.
- Recently discovered zero-day vulnerabilities found in in-scope assets within 14 days after the public release of a patch or mitigation may be reported, but are usually not eligible for a bounty.
- Vulnerabilities that only work on software that no longer receive security updates.
- Reports that state that software is out of date/vulnerable without a proof-of-concept.
Repositories
- Paths marked as out of scope for an in-scope repository, as listed in that asset's description.
- Vulnerabilities that originate in the developer's own code rather than in the framework itself. The framework running developer-supplied code, configuration, or integrations as designed is expected behavior.
- Prompt injection and unsafe model behavior. Frameworks are not designed to protect against a model being manipulated through its inputs or producing harmful or unexpected output, so these are not vulnerabilities on their own. Prompt injection is in scope only when it is the delivery mechanism for exploiting an actual vulnerability in a framework's code.
- Vulnerabilities that only occur under non-default configurations, whether by intentionally configuring an application insecurely or by relaxing a secure default.
- Vulnerabilities in deprecated functionality.
- Vulnerabilities in archived repositories.
- Vulnerabilities in third-party dependencies, unless the impact can be demonstrated through LangChain's code.
- Vulnerabilities inherited from the upstream project a repository was forked from, unless the impact can be demonstrated through LangChain's code.
- Leaked secrets or credentials with no meaningful impact.
- Templates, examples, demo, starter projects, which are not part of a framework's code.
This program follows Intigriti's triage standards based on the proof of concept.
Where can I find more information about how to set up and use LangChain's open-source frameworks?
Our documentation at https://docs.langchain.com/ covers how to set up and use LangChain's open-source frameworks.
Where can I find security advisories for LangChain's open-source projects?
All advisories are published as GitHub Security Advisories on the repository that was affected. You can find them under the Security tab of each repository, at github.com/langchain-ai/<repository>/security/advisories.
How do I know what a given project considers a security vulnerability?
Some repositories include a THREAT_MODEL.md, either under .github/ or within a subproject. Where present, it describes the project's trust boundaries, the security concerns that apply to it, and the risks that have already been accepted. Reviewing it before submitting will help you understand what does and does not count as a vulnerability for that project.
For obvious reasons we can only allow submissions or applications for our program with a valid Intigriti account.
It will only take 2 minutes to create a new one or even less to log in with an existing account, so don't hesitate and let's get started. We would be thrilled to have you as part of our community.






























