Skip to content
← archivevulnerability · 24 Sep 2026 · 19:25 UTC

GHSA-g28h-2cmm-rj9x: langchain-nvidia-ai-endpoints has local file disclosure through VLM image inputs

HIGHHigh-risk vulnerability — CVSS 7.5

last 60 dispatches · spectrum

## Summary `langchain-nvidia-ai-endpoints` versions before 1.4.2 accepted local filesystem paths as image inputs for Vision Language Model (VLM) requests. If an application passed attacker-controlled image input to `ChatNVIDIA` or VLM reranking APIs, an attacker could cause files readable by the application process to be read and included in the outbound request to the configured NVIDIA/NIM model endpoint. ## Impact Applications are affected if they use VLM image inputs with `ChatNVIDIA` or `NVIDIARerank` and allow untrusted users to control image URLs or document image metadata. …

grounded ✓primary source ↗
Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected