CVE-2026-34070 | langchain-ai langchain up to 1.2.21 load_prompt/load_prompt_from_config path traversal (GHSA-qh6h-p6c9-ff54)
A vulnerability classified as critical has been found in langchain-ai langchain up to 1.2.21. Affected by this issue is the function load_prompt/load_prompt_from_config. The manipulation leads to path traversal.
This vulnerability is documented as CVE-2026-34070. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.