M
MercyNews
Home
Back
LangGrinch Exploit Targets LangChain Core (CVE-2025-68664)
Technology

LangGrinch Exploit Targets LangChain Core (CVE-2025-68664)

Hacker NewsDec 25
3 min read
📋

Key Facts

  • ✓ A vulnerability identified as CVE-2025-68664 affects LangChain Core.
  • ✓ The vulnerability is nicknamed 'LangGrinch'.
  • ✓ The issue allows for the extraction of secrets.
  • ✓ The vulnerability was disclosed on December 25, 2025.
  • ✓ Discussion regarding the vulnerability appeared on Hacker News.

In This Article

  1. Quick Summary
  2. Vulnerability Details
  3. Public Disclosure and Reaction
  4. Impact on the Ecosystem
  5. Conclusion

Quick Summary#

A critical security vulnerability, designated as CVE-2025-68664, has been identified in the LangChain Core library. Dubbed 'LangGrinch', this exploit targets the framework's ability to handle sensitive data, potentially allowing unauthorized access to secrets.

The vulnerability was publicly disclosed on December 25, 2025. Following the disclosure, the technical community engaged in discussions regarding the implications of the flaw on the AI development landscape. The exploit specifically affects the core components of the LangChain ecosystem.

Vulnerability Details#

The vulnerability, tracked as CVE-2025-68664, represents a significant security flaw within the LangChain Core. The primary impact of this vulnerability is the potential for secret extraction. This means that under specific conditions, an attacker could retrieve credentials or other sensitive data that should remain secure.

The flaw was highlighted in a security advisory released on Christmas Day. The timing of the release drew attention from the cybersecurity community. The vulnerability affects the fundamental operations of the library, which is widely used for building applications powered by large language models.

Public Disclosure and Reaction#

The discovery of the LangGrinch vulnerability was made public through a specific blog post. This initial disclosure was quickly followed by a discussion thread on Hacker News. The thread on Hacker News garnered significant attention, receiving 4 points and generating 1 comment shortly after publication.

The community reaction focused on the implications of a core library vulnerability. The discussion highlighted concerns regarding:

  • The security of AI agents built on LangChain
  • Best practices for managing secrets in development environments
  • The response time of the LangChain maintainers

Impact on the Ecosystem#

LangChain serves as a foundational block for many AI applications. A vulnerability in its core library affects a wide array of downstream projects. Developers relying on the library for production systems face immediate risks regarding data integrity and confidentiality.

The discovery of CVE-2025-68664 serves as a reminder of the volatility inherent in emerging technologies. As the ecosystem matures, rigorous security auditing becomes increasingly critical to prevent exploits like the LangGrinch incident.

Conclusion#

The LangGrinch vulnerability (CVE-2025-68664) underscores the importance of security vigilance in the AI sector. The incident, disclosed on December 25, 2025, serves as a critical case study for developers and security researchers alike. Moving forward, the focus remains on the remediation of this flaw and the strengthening of security protocols within the LangChain ecosystem.

Continue scrolling for more

AI Transforms Mathematical Research and Proofs
Technology

AI Transforms Mathematical Research and Proofs

Artificial intelligence is shifting from a promise to a reality in mathematics. Machine learning models are now generating original theorems, forcing a reevaluation of research and teaching methods.

Just now
4 min
172
Read Article
Ben Horowitz says that investing teams shouldn't be 'too much bigger than basketball teams'
Technology

Ben Horowitz says that investing teams shouldn't be 'too much bigger than basketball teams'

Ben Horowitz said investment teams should be the size of a playing five in basketball. Phillip Faraone/Getty Images for WIRED Ben Horowitz said his rule of thumb is about five people on an investing team. He said Andreessen Horowitz maintains lean teams and strong communication across verticals. AI tools are enabling startups and VCs to thrive with fewer employees. Ben Horowitz is a big fan of tiny teams. On an episode of the A16z podcast, the Andreessen Horowitz cofounder shared how his venture capital firm maintains a lean operation despite being one of the world's largest. "An investing team shouldn't be too much bigger than a basketball team," he said, referring to advice he got from famed American investor David Swensen in 2009. He added, "A basketball team is five people who start, and the reason for that is the conversation around the investments really needs to be a conversation." Horowitz cofounded the Silicon Valley VC firm with Marc Andreessen in 2009. Before A16Z, he ran enterprise software company Opsware, which Hewlett-Packard acquired. A16z has backed marquee companies including Meta, Airbnb, GitHub, and Coinbase. The VC said he always kept the basketball team size in mind but also knew that the firm had to expand to keep up with how "software was eating the world," his signature phrase. The solution was to split the firm into different investment verticals. To maintain good communication, staff attend other teams' meetings when investment themes overlap. The firm also organizes a two to three-day offsite twice a year, "with not much agenda." Horowitz said that people who join them from other firms say that A16Z has "less politics" than firms with 10 or 11 people because his firm has a culture where politicking is "disincentivized." A16z might have been early to the tiny team trend, but it's catching on fast with VCs and startups across the world. Startups are actively seeking to stay small, with many having fewer than 10 people. Founders told Business Insider that AI and vibe coding tools have boosted their productivity, allowing them to get things done with far fewer people. Less politics and bureaucracy are also big pluses, they say. "We're going to see 10-person companies with billion-dollar valuations pretty soon," OpenAI CEO Sam Altman said in February 2024. "In my little group chat with my tech CEO friends, there's this betting pool for the first year there is a one-person billion-dollar company, which would've been unimaginable without AI. And now will happen." Read the original article on Business Insider

1h
3 min
0
Read Article
Tempest: American Missile Buggy Scores 20+ Kills in Ukraine
World_news

Tempest: American Missile Buggy Scores 20+ Kills in Ukraine

A new American off-road buggy equipped with guided missiles has entered service in Ukraine, where crews report significant success against Russian drone threats. The Tempest system offers mobile air defense against Shahed loitering munitions.

1h
5 min
3
Read Article
Iran’s Leaders May Survive Protests. But Anger Will Likely Persist.
Politics

Iran’s Leaders May Survive Protests. But Anger Will Likely Persist.

Its security forces have brutally defended the Islamic Republic, but the protests show that many Iranians consider it stagnant and ideologically hollow.

1h
3 min
0
Read Article
Creator income inequality is rising as top influencers rake in big paydays from brands
Economics

Creator income inequality is rising as top influencers rake in big paydays from brands

Top creator Jimmy Donaldson, a.k.a. MrBeast, at the "Beast Games" season 2 premiere. JC Olivera/Variety via Getty Images Creator income inequality is rising, with the top 1% earning 21% of brand spending, per new CreatorIQ data. The trend has continued in each of the last two years. Big brands often favor top creators, making it harder for smaller influencers to compete. Creators are raking in the ad dollars — but the wealth is being shared less and less equally. New data from the influencer-marketing platform CreatorIQ shows that the income gap in the creator economy is widening. The top 10% of creators on CreatorIQ's platform received 62% of ad payments in 2025, up from 53% in 2023. Similarly, the top 1% received 21% of the total ad payment volume, up from 15% in 2023. CreatorIQ, which included the 2025 data in a new report released on Wednesday, examined 65,000 payments over a three-year period from brands and agencies to creators who received flat payments through its software. The data reflects an overall pattern in the creator economy. Brands are shifting more of their marketing dollars to creators, with payments more than doubling over the last two years in CreatorIQ's dataset. Overall, US advertiser spending on creators was expected to hit $37 billion in 2025, according to a November report from the Interactive Advertising Bureau. At the same time, much of the ad money is going to a relatively narrow segment of top talent. While many creators also make money outside influencer marketing — such as from subscriptions or direct payments from platforms like YouTube — brand sponsorships are generally the industry's top revenue source. Jasmine Enberg, cofounder and co-CEO of Scalable, a new media company focused on the creator economy, said the numbers show the industry is starting to resemble traditional entertainment, where top players rake in substantial sums, leaving smaller ones to compete for the leftovers. Enberg said the divide would only grow as big creators get larger projects, such as TV campaigns or Netflix deals. "We need to empower brands to diversify their investment more confidently," Brit Starr, CMO of CreatorIQ, said of the industry. CreatorIQ's survey of 300 creators found that only 11% earned $100,000 or more. About one-quarter of the creators surveyed fell into each of the "$50,000 to $100,000" and the "$25,000 to $50,000" categories. CreatorIQ's report included additional data points that help explain the current dynamics of the creator economy. The number of creators receiving payments within CreatorIQ's network more than doubled from 2023 to 2025, which could indicate an overall surge in influencers entering the market. While the average earnings per creator rose to $11,400 in 2025 from $9,200 in 2023, the median actually declined slightly, from $3,500 to $3,000. That suggests that top creators are pulling the average higher, while the typical creator is earning less. What's driving the pay gap Enberg said major advertisers have contributed to the sector's income inequality because they're more likely to allocate their budgets to a small number of top creators. Talent managers who spoke with Business Insider said earnings distribution had been lumpy. Budgets have definitely grown, but they haven't kept pace with the expansion of the creator population, said Kyle Hjelmeseth, CEO of G&B Digital Management. "There are now many more small accounts that will take $25 to post, for example," he said. Meanwhile, advertisers often spend a large chunk of their influencer budgets directly with social media platforms, making it harder for creators — especially smaller ones — to develop direct and potentially lasting relationships with brands, creator-industry insiders said. Becca Bahrke, the CEO of Illuminate Social, a creator management firm, said the CreatorIQ payment concentration data reflect what she's seeing among her own clients. She said she'd seen some full-time creators take the off-ramp to a different job. "You may have earned over $400,000 in one year, but if you're not showing up consistently on the platform, treating it as a full-time job, you can see the earnings fall," Bahrke said. "It's a lot of work. It's not for the faint of heart." Read the original article on Business Insider

1h
3 min
0
Read Article
KB Files Patent for Hybrid Stablecoin Credit Card
Economics

KB Files Patent for Hybrid Stablecoin Credit Card

South Korean financial giant KB has filed a patent application for a groundbreaking hybrid payment system. This technology aims to bridge the gap between digital assets and traditional finance.

1h
5 min
7
Read Article
Politics

East Jerusalem Schools Strike Over Teacher Permits

Classes for approximately 20,000 students were suspended across private institutions in East Jerusalem as educators and administrators protest what they describe as arbitrary new limitations on work permits for teachers residing in the West Bank.

1h
3 min
8
Read Article
Spanish Housing Crisis Drives Economic Pessimism
Economics

Spanish Housing Crisis Drives Economic Pessimism

The ongoing housing crisis in Spain is significantly impacting citizens' economic outlook, with recent surveys showing a dramatic decline in consumer confidence as property prices and rents continue their relentless climb.

1h
5 min
7
Read Article
Jorge Verstrynge, politólogo: “La derecha española enloquece cuando ve el poder cerca”
Politics

Jorge Verstrynge, politólogo: “La derecha española enloquece cuando ve el poder cerca”

‘Rara avis’ política, nacionalbolchevique y populista, fue secretario general de Alianza Popular bajo la presidencia de Manuel Fraga y luego transitó hacia espacios de izquierda. Ahora publica sus memorias

2h
3 min
0
Read Article
Cristina Araújo's 'Distancia de fuga' Explores Heart's Indecisions
Culture

Cristina Araújo's 'Distancia de fuga' Explores Heart's Indecisions

Cristina Araújo returns with a masterful second novel, dissecting the complexities of the human heart against a backdrop of modern anxieties. Discover the unique narrative style that defines 'Distancia de fuga'.

2h
5 min
7
Read Article
🎉

You're all caught up!

Check back later for more stories

Back to Home