Database/AI/ML frameworks & serving
LangChain4j agentic: unsafe Jackson default typing in AgenticScope deserialization allows arbitrary class instantiation
Impact
AgenticScopeSerializer.fromJson in the LangChain4j agentic module deserializes persisted agent scope with Jackson default typing enabled, so a crafted record in the persistence store can instantiate arbitrary classes on the JVM running the agent. On a GPU fleet that JVM typically sits next to model endpoints and holds their credentials, so class instantiation there is a foothold in the serving tier rather than in a sandbox. The practical reach is narrow: AgenticScope persistence is opt-in, and the attacker must already be able to write to that store, which is why the record scores 1.2. A proof of concept has been published.
Who can reach it
An attacker who can already write to the AgenticScope persistence store of an application that has explicitly enabled AgenticScope persistence. Not reachable in the default configuration, and not reachable by an unauthenticated network caller.
What to do
Upgrade to langchain4j 1.5.3-beta11, 1.11.10-beta19 or 1.18.1-beta28 depending on your release line; all maintained lines are patched. Rebuild and redeploy the agent service. If you cannot upgrade now, the effective mitigation is the same as the precondition: keep the AgenticScope store writable only by the application itself, or leave persistence disabled.
References
Related entries
- llama.cpp: a crafted GGUF file trips a reachable assertion and aborts the process loading itCVE-2026-52131 · llama.cpp (gguf_reader::read GGUF model file parser)Unscored
- llama.cpp server: negative top_n on /rerank drives an unbounded allocation and denial of serviceCVE-2026-52132 · llama.cpp server /rerank endpoint (top_n handling under --reranking)Unscored
- Hugging Face Transformers: load_custom_generate writes remote code to disk before the trust checkCVE-2026-80047 · Hugging Face Transformers (dynamic_module_utils.py, load_custom_generate remote-code cache)Unscored
- SGLang: unauthenticated pickle deserialization on /update_weights_from_tensor gives code executionCVE-2026-86793 · SGLang inference server (/update_weights_from_tensor, SafeUnpickler)Unscored
- Jupyter Notebook (untrusted notebooks): Untrusted notebook executes JavaScript in the user's session on openCVE-2021-32798 · Jupyter Notebook (untrusted notebooks)Critical
- MLflow: Absolute path traversal prior to 2.5.0CVE-2023-3765 · MLflowCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.