Avatar for the langchain-ai user
langchain-ai
langchain
BlogDocsChangelog

fix(core): backport path-traversal fix to v0.3 (CVE-2026-34070, GHSA-qh6h-p6c9-ff54)

#37233Merged
Comparing
erny:backport/cve-2026-34070-load-prompt-path-traversal
(
35d7a0d
) with
v0.3
(
cccefce
)
CodSpeed Performance Gauge
×3.1
Improvement
13
Skipped
2

Benchmarks

15 total
test_import_time[HumanMessage]
libs/core/tests/benchmarks/test_imports.py
CodSpeed Performance Gauge
×3.1
669.4 ms*216.3 ms
test_import_time[tool]
libs/core/tests/benchmarks/test_imports.py
CodSpeed Performance Gauge
×2.7
1,402.4 ms*513 ms
test_import_time[LangChainTracer]
libs/core/tests/benchmarks/test_imports.py
CodSpeed Performance Gauge
×2.7
1,167.5 ms*430.3 ms
test_import_time[ChatPromptTemplate]
libs/core/tests/benchmarks/test_imports.py
CodSpeed Performance Gauge
×2.6
1,611.8 ms*612.3 ms
test_import_time[InMemoryRateLimiter]
libs/core/tests/benchmarks/test_imports.py
CodSpeed Performance Gauge
×2.6
443.6 ms*168.5 ms
test_import_time[BaseChatModel]
libs/core/tests/benchmarks/test_imports.py
CodSpeed Performance Gauge
×2.6
1,406.5 ms*534.4 ms
test_import_time[RunnableLambda]
libs/core/tests/benchmarks/test_imports.py
CodSpeed Performance Gauge
×2.6
1,267.3 ms*486.2 ms
test_import_time[Runnable]
libs/core/tests/benchmarks/test_imports.py
CodSpeed Performance Gauge
×2.6
1,264.3 ms*488.7 ms
test_import_time[PydanticOutputParser]
libs/core/tests/benchmarks/test_imports.py
CodSpeed Performance Gauge
×2.5
1,381.6 ms*545.6 ms
test_import_time[InMemoryVectorStore]
libs/core/tests/benchmarks/test_imports.py
CodSpeed Performance Gauge
×2.4
1,497.8 ms*629.2 ms
test_import_time[Document]
libs/core/tests/benchmarks/test_imports.py
CodSpeed Performance Gauge
×2.2
483.2 ms*215.3 ms
test_async_callbacks_in_sync
libs/core/tests/benchmarks/test_async_callbacks.py
CodSpeed Performance Gauge
×2.1
54.6 ms*25.8 ms
test_import_time[CallbackManager]
libs/core/tests/benchmarks/test_imports.py
CodSpeed Performance Gauge
+80%
811.7 ms*451.2 ms
test_create_agent_instantiation_with_middleware
libs/langchain_v1/tests/benchmarks/test_create_agent.py
Skipped
15.1 ms*
test_create_agent_instantiation
libs/langchain_v1/tests/benchmarks/test_create_agent.py
Skipped
4.1 ms*

Commits

Click on a commit to change the comparison range
Base
master
cccefce
×3.1
fix(core): validate paths in `prompt.save` and `load_prompt`, deprecate methods (#36200)
35d7a0d
1 month ago
by ccurme
© 2026 CodSpeed Technology
Home Terms Privacy Docs