This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+11 more
Affected surfaces
Summary
AI summaryConfined file‑search results and tightened Anthropic allowed prefixes.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Bugfix | Medium |
Confines file-search results to prevent unintended data exposure. Confines file-search results to prevent unintended data exposure. Source: llm_adapter@2026-06-12 Confidence: high |
— |
| Bugfix | Medium |
Tightens anthropic `allowed_prefixes` for stricter prefix validation. Tightens anthropic `allowed_prefixes` for stricter prefix validation. Source: llm_adapter@2026-06-12 Confidence: high |
— |
Full changelog
Changes since langchain==1.3.8
release(anthropic): 1.4.6 (#38105)
release(langchain): 1.3.9 (#38104)
fix(langchain,anthropic): confine file-search results and tighten anthropic allowed_prefixes (#38106)
Security Fixes
- Confined file‑search results and tightened Anthropic `allowed_prefixes` to mitigate unauthorized access.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Earlier breaking changes
- vlangchain-core==1.4.0 Deletes schema items marked for removal in schemas.py
- vlangchain-core==1.4.0 Deletes function_calling.py utils marked for removal
- vlangchain-core==1.4.0 Deletes get_relevant_documents function from API
- vlangchain-core==1.4.0 Deletes pydantic_v1 module entirely from codebase
- vlangchain-core==1.4.0 Deletes BaseMemory module, moved to langchain-classic
Beta — feedback welcome: [email protected]