CVE-2026-26013 | langchain-ai langchain up to 1.2.10 Image Parser ChatOpenAI.get_num_tokens_from_messages image_url server-side request forgery (GHSA-2g6r-c272-w58r)
A vulnerability was found in langchain-ai langchain up to 1.2.10 and classified as critical. This impacts the function ChatOpenAI.get_num_tokens_from_messages of the component Image Parser. Such manipulation of the argument image_url leads to server-side request forgery.
This vulnerability is listed as CVE-2026-26013. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.