Skip to content

Conversation

@awilfox
Copy link
Member

@awilfox awilfox commented Jan 5, 2026

This is to fix GHSA-c67j-w6g6-q2cm, aka CVE-2025-68664.

It is unlikely this would affect Willa, as we do not deserialise untrusted documents (all documents are from the ETL pipeline). However, we want to ensure we are not vulnerable in the future (nor as functionality expands).

This is to fix GHSA-c67j-w6g6-q2cm, aka CVE-2025-68664.

It is unlikely this would affect Willa, as we do not deserialise untrusted
documents (all documents are from the ETL pipeline).  However, we want to
ensure we are not vulnerable in the future (nor as functionality expands).
@awilfox awilfox merged commit 497cda4 into main Jan 5, 2026
9 checks passed
@awilfox awilfox deleted the awilfox/langchain-125-cve branch January 5, 2026 19:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants