Live data from Hacker News

Critical vulnerability in LangChain – CVE-2025-68664

cyata.ai

31–40 of 93 posts

Re: Critical vulnerability in LangChain – CVE-2025-68664

#31
post #29

> The blast radius is scale Ugh. I’m a native English speaker and this sounds wrong , massaged by LLM or not. “Large blast radius” would be a good substitute. I am happy this whole issue doesn’t affect me, so I can stop reading when I don’t like the writing.

Makes you think a human wrote it, which for an article on a .ai domain is kind of shocking!

Re: Critical vulnerability in LangChain – CVE-2025-68664

#32
post #11

Earlier quoted context omitted.

you can use chatgpt to reverse the prompt

Not sure if it's a joke, but I don't think LLM is a bijective function.

If you had all the token probabilities it would be bijective. There was a post about this here some time back.

Re: Critical vulnerability in LangChain – CVE-2025-68664

#34
post #22
post #18

Earlier quoted context omitted.

> I prefer reading the LLM output for accessibility reasons. And that's completely fine! If you prefer to read CVEs that way, nobody is going to stop you from piping all CVE descriptions you're interested in through a LLM. However, having it processed by a LLM is essentially a one-way operation. If some people prefer the original and some others prefer the LLM output, the obvious move is to share the original with th…

Yes, framed as you stated it is indeed a win-win. However, there will be cases where lacking the LLM output, there isn't any output at all. Creating a stigma over technology which is easily observed as being, in some form, accessible is expected in the world we live. As it is on HN. Not to say you are being any type of anything, I just don't believe anyone has given it all that much thought. I read the complaints and…

> However, there will be cases where lacking the LLM output, there isn't any output at all.

Why would there be? You're using something to prompt the LLM, aren't you - what's stopping you from sharing the input?

The same logic can be applied in an even larger extent to foreign-language content. I'd 1000x rather have a "My english not good, this describe big LangChain bug, click if want Google Translate" followed by a decent article written in someone's native Chinese, than a poorly-done machine translation output. At least that way I have the option of putting the source text in different translation engines, or perhaps asking a bilingual friend to clarify certain sections. If all you have is the English machine translation output, then you're stuck with that. Something was mistranslated? Good luck reverse engineering the wrong translation back to its original Chinese and then into its proper English equivalent! Anyone who has had the joy to deal with "English" datasheets for Chinese-made chips knows how well this works in practice.

You are definitely bringing up a good point concerning accessibility - but I fear using LLMs for this provides fake accessibility. Just because it results in well-formed sentences doesn't mean you are actually getting something comprehensible out of it! LLMs simply aren't good enough yet to rely on them not losing critical information and not introducing additional nonsense. Until they have reached that point, their user should always verify its output for accuracy - which on the author side means they were - by definition - also able to write it on their own, modulo some irrelevant formatting fluff. If you still want to use it for accessibility, do so on the reader side and make it fully optional: that way the reader is knowingly and willingly accepting its flaws.

The stigma on LLM-generated content exists for a reason: people are getting tired of starting to invest time into reading some article, only for it to become clear halfway through that it is completely meaningless drivel. If >99% of LLM-generated content I come across is an utter waste of my time, why should I give this one the benefit of the doubt? Content written in horribly-broken English at least shows that there is an actual human writer investing time and effort into trying to communicate, instead of it being yet another instance of fully-automated LLM-generated slop trying to DDoS our eyeballs.

Re: Critical vulnerability in LangChain – CVE-2025-68664

#35
LLM slop. At least one clear error (hallucination): "’Twas the night before Christmas, and I was doing the least festive kind of work: staring at serialization"

Per disclosure timeline the report was made on December 4, it was definitely not the night before Christmas when you were doing the work then.

Re: Critical vulnerability in LangChain – CVE-2025-68664

#37
post #26

Earlier quoted context omitted.

Can you elaborate? Fairly new to langchain, but didn't realize it had any sort of stereotypical type of user.

I'll admit that I haven't looked it in a while, but as originally released, it was a textbook example on how to complicate a fundamentally simple and well-understood task (text templates, basically) with lots of useless abstractions that made it all sound more "enterprise". People would write complicated langchains, but then when you looked under the hood all it was doing is some string concatenation, and the result…

What do you suggest instead? Handrolled code with “import openai”? BAML?

Re: Critical vulnerability in LangChain – CVE-2025-68664

#38
post #13

Earlier quoted context omitted.

I would rather read succinct English written by a non-native speaker filled with broken grammar than overly verbose but well-spelled AI slop. Heck, just share the prompt itself! If you can't be bothered to have a human write literally a handful of lines of text, what else can't you be bothered to do? Why should I trust that your CVE even exists at all - let alone is indeed "critical" and worth ruining Christmas over?

You wouldn't complain as much if it were merely poorly written by a human. It gets the information across. The novelty of complaining about a new style of bad writing is being overdone by a lot of people, particularly on HN.

> You wouldn't complain as much if it were merely poorly written by a human.

Obviously.

> It gets the information across.

If it is poorly written by a human? Sure!

> The novelty of complaining about a new style of bad writing

But it's not a "new style of bad writing", is it?

The problem is that LLM-generated content is more often than not wrong. It is only worth reading if a human has invested time into post-processing it. However, LLMs make badly-written low-quality content look the same as badly-written high-quality content or decently-written high-quality content. It is impossible for the reader to quickly distinguish properly post-processed LLM output from time-wasting slop.

On the other hand, if its written by a human it is often quite easy to distinguish badly-written low-quality content from badly-written high-quality content. And the writing was never the important part: it has always been about the content. There are plenty of non-native English tech enthusiasts writing absolute gems in the most broken English you can imagine! Nobody has ever had trouble distinguishing those from low-quality garbage.

But the vast majority of LLM-generated content I come across on the internet is slop and a waste of my time. My eyeballs are being DDoSed. The only logical action upon noticing that something is LLM-generated content is to abort reading it and assume it is slop as well. Like it or not, LLMs have become a sign of poor quality.

By extension, the issue with using LLMs for important content is that you are making it look indistinguishable from slop. You are loudly signaling to the reader that it isn't worth their time. So yes, if you want people to read it, stick to bad human writing!

Re: Critical vulnerability in LangChain – CVE-2025-68664

#39

The best part about this is that you know the type of people/companies using langchain are likely the type that are not going to patch this in a timely manner.

Yep, not sure why anyone is using it still.

These guys raised $125M at $1.3B post on $12M ARR? What.

> Today, langchain and langgraph have a combined 90M monthly downloads, and 35 percent of the Fortune 500 use our services

What? This seems crazy. Maybe I'm blind, but I don't see the long term billion dollar business op here.

Leftpad also had those stats, iirc.

Re: Critical vulnerability in LangChain – CVE-2025-68664

#40
post #39

Earlier quoted context omitted.

Yep, not sure why anyone is using it still.

These guys raised $125M at $1.3B post on $12M ARR? What. > Today, langchain and langgraph have a combined 90M monthly downloads, and 35 percent of the Fortune 500 use our services What? This seems crazy. Maybe I'm blind, but I don't see the long term billion dollar business op here. Leftpad also had those stats, iirc.

They were the first, very very early in the gpt hype start.
Post reply on HN