Skip to content

GenAI Red Team Handbook: Exploitation of Sandbox with CVE-2025-68664 (langchain-core 1.2.4)#784

Open
felipepenha wants to merge 15 commits into
OWASP:mainfrom
felipepenha:CVE-2025-68664
Open

GenAI Red Team Handbook: Exploitation of Sandbox with CVE-2025-68664 (langchain-core 1.2.4)#784
felipepenha wants to merge 15 commits into
OWASP:mainfrom
felipepenha:CVE-2025-68664

Conversation

@felipepenha
Copy link
Copy Markdown

@felipepenha felipepenha commented Dec 27, 2025

GenAI Red Team Handbook_ Exploitation of Sandbox with CVE-2025-68664 (langchain-core 1.2.4)

Key Changes:

  • List major changes and core updates
    • initiatives/genai_red_team_handbook/sandboxes/llm_local_langchain_core_v1.2.4
    • initiatives/genai_red_team_handbook/exploitation/CVE-2025-68664
  • Keep each line under 80 characters
  • Focus on the "what" and "why"
    Exploitation of Sandbox with CVE-2025-68664 (langchain-core<1.2.5)

Added:

  • New features/functionality
  • New files/configurations
  • New dependencies

@felipepenha
Copy link
Copy Markdown
Author

This will be kept as a Draft PR, until after #781 is approved and merged.

@rossja rossja marked this pull request as ready for review December 28, 2025 02:23
@rossja rossja self-requested a review as a code owner December 28, 2025 02:23
@felipepenha felipepenha requested a review from rossja December 28, 2025 03:20
@felipepenha
Copy link
Copy Markdown
Author

felipepenha commented Dec 28, 2025

I decided to rename dir CVE-2025-68664 to LangGrinch to make it easier to identify and differentiate in the future. The CVE id is still present in the documentation, though. I think having dir names as CVE codes may not be the best idea. Better to have nicknames and/or short descriptors.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants