
Technical analysis of the LangChain serialization injection vulnerability CVE-2025-68664.
This repository contains a technical report analyzing CVE-2025-68664, also known as LangGrinch, a serialization injection vulnerability affecting LangChain Core.
The report explains the vulnerability background, root cause, exploitation flow, threat model, mitigation strategies, and real-world security impact on LLM-based applications.
The full report is available here:
This project is for educational and defensive security research purposes only. It does not provide instructions for unauthorized access or real-world exploitation.