CVE-2026-26019 | langchain-ai langchainjs up to 1.1.13 URL Validation String.startsWith server-side request forgery
A vulnerability was found in langchain-ai langchainjs up to 1.1.13. It has been rated as critical. Affected by this vulnerability is the function String.startsWith of the component URL Validation Handler. The manipulation leads to server-side request forgery.
This vulnerability is listed as CVE-2026-26019. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.