Live data from Hacker News

Critical vulnerability in LangChain – CVE-2025-68664

cyata.ai

71–80 of 93 posts

Re: Critical vulnerability in LangChain – CVE-2025-68664

#71
post #62

Earlier quoted context omitted.

JSON Structured Output from OpenAI was released a year after the first LangChain release. I think structured output with schema validation mostly replaces the need for complex prompt frameworks. I do look at the LC source from time to time because they do have good prompts backed into the framework.

To this day many good models don't support structured outputs (say Opus 4.5) so it's not a panacea you can count on in production. The bigger problem is that LangChain/Python is the least set up to take advantage of strong schemas even when you do have it. Agree about pillaging for prompts though.

> so it's not a panacea you can count on in production.

OpenAI and Gemini models can handle ridiculously complicated and convoluted schemas, if I needed complicated JSON output I wouldn’t use anything that didn’t guarantee it.

I have pushed Gemini 2.5 Pro further than I thought possible when it comes to ridiculously over complicated (by necessity) structured output.

Re: Critical vulnerability in LangChain – CVE-2025-68664

#72
post #68

Earlier quoted context omitted.

Python being a very bad language for LLM stuff is a hot take I haven’t heard before. Your arguments sound mostly like personal preferences that apply to any problem, not just agentic / LLM. If we’re going to throw experience around, after 30+ years of coding experience, I really don’t care too much anymore as long as it gets the job done and it doesn’t get in the way. LangChain is ok, LangGraph et al I try to avoid l…

I used to write web apps in C++, so I totally understand not caring if it gets the job done. I guess the difference where I draw the line is that LLMs are inherently random I/O so you have to treat them like UI, or the network, where you really have no idea what garbage is gonna come in and you have to be defensive if you're going to build something complex -- otherwise, you as a programmer will not be able to unders…

What does static type systems provide you with that, say, using structured input / output using pydantic doesn’t?

I just don’t follow your logic of “LLMs are inherently random IO” (ok, I can somehow get behind that, but structured output is a thing) -> “you have to treat them like UI / network” (ok, yes, it’s untrusted) -> static typing solves everything (how exactly?)

This just seems like another “static typing is better than dynamic typing” debate which really doesn’t have a lot to do with LLMs.

Re: Critical vulnerability in LangChain – CVE-2025-68664

#73
post #60

Earlier quoted context omitted.

I somewhat take issue as a LangChain hater + Mastra lover with 20+ years of coding experience and coding awards to my name (which I don't care about, I only mention it for context). Langchain is `left-pad` -- a big waste of your time, and Mastra is Next.js -- mostly saving you infrastructure boilerplate if you use it right. But I think the primary difference is that Python is a very bad language for agent/LLM stuff (…

Python being a very bad language for LLM stuff is a hot take I haven’t heard before. Your arguments sound mostly like personal preferences that apply to any problem, not just agentic / LLM. If we’re going to throw experience around, after 30+ years of coding experience, I really don’t care too much anymore as long as it gets the job done and it doesn’t get in the way. LangChain is ok, LangGraph et al I try to avoid l…

he says its bad for agents, nit 'LLM stuff'. python is fine to throw task to the GPU. it is absolutely dreadful at any real programming. so if you want to write an agent that _uses_ LLMs etc like an agent, there are much better languages, for performance, safety and your sanity.

Re: Critical vulnerability in LangChain – CVE-2025-68664

#74

Earlier quoted context omitted.

Python being a very bad language for LLM stuff is a hot take I haven’t heard before. Your arguments sound mostly like personal preferences that apply to any problem, not just agentic / LLM. If we’re going to throw experience around, after 30+ years of coding experience, I really don’t care too much anymore as long as it gets the job done and it doesn’t get in the way. LangChain is ok, LangGraph et al I try to avoid l…

he says its bad for agents, nit 'LLM stuff'. python is fine to throw task to the GPU. it is absolutely dreadful at any real programming. so if you want to write an agent that _uses_ LLMs etc like an agent, there are much better languages, for performance, safety and your sanity.

so the argument boils down to “untyped languages are dreadful for real programming” ?

Re: Critical vulnerability in LangChain – CVE-2025-68664

#75
post #18
post #14

Earlier quoted context omitted.

I prefer reading the LLM output for accessibility reasons. More importantly though, the sheer amount of this complaint on HN has become a great reason not to show up.

> I prefer reading the LLM output for accessibility reasons. And that's completely fine! If you prefer to read CVEs that way, nobody is going to stop you from piping all CVE descriptions you're interested in through a LLM. However, having it processed by a LLM is essentially a one-way operation. If some people prefer the original and some others prefer the LLM output, the obvious move is to share the original with th…

Well, no.

Because authors do two things typically when they use an LLM for editing:

- iterate multiple rounds

- approve the final edit as their message

I can’t do either of those things myself — and your post implicitly assumes there’s underlying content prior to the LLM process; but it’s likely to be iterated interactions with an LLM that produces content at all — ie, there never exists a human-written rough draft or single prompt for you to read, either.

So your example is a lose-lose-lose: there never was a non-LLM text for you to read; I have no way to recreate the author’s ideas; and the author has been shamed into not publishing because it doesn’t match your aesthetics.

Your post is a classic example of demanding everyone lose out because something isn’t to your taste.

Re: Critical vulnerability in LangChain – CVE-2025-68664

#76
post #37
post #26

Earlier quoted context omitted.

I'll admit that I haven't looked it in a while, but as originally released, it was a textbook example on how to complicate a fundamentally simple and well-understood task (text templates, basically) with lots of useless abstractions that made it all sound more "enterprise". People would write complicated langchains, but then when you looked under the hood all it was doing is some string concatenation, and the result…

What do you suggest instead? Handrolled code with “import openai”? BAML?

Have you heard of `def`?

Re: Critical vulnerability in LangChain – CVE-2025-68664

#77
post #38

Earlier quoted context omitted.

You wouldn't complain as much if it were merely poorly written by a human. It gets the information across. The novelty of complaining about a new style of bad writing is being overdone by a lot of people, particularly on HN.

> You wouldn't complain as much if it were merely poorly written by a human. Obviously. > It gets the information across. If it is poorly written by a human? Sure! > The novelty of complaining about a new style of bad writing But it's not a "new style of bad writing", is it? The problem is that LLM-generated content is more often than not wrong . It is only worth reading if a human has invested time into post-process…

> There are plenty of non-native English tech enthusiasts writing absolute gems in the most broken English you can imagine! Nobody has ever had trouble distinguishing those from low-quality garbage.

Your entire theory about LLMs seems to rely on that… but it’s just not true, eg, plenty of quality writing with low technical merit is making a fortune while genuinely insightful broken English languishes in obscurity.

You’re giving a very passionate speech about how no dignified noble would be dressed in these machine-made fabrics, which while some are surely as finely woven as those by any artisan, bear the unmistakable stain of association with plebs dressed in machine-made fabrics.

I admire the commitment to aesthetics, but I think you’re fighting a losing war against the commoditization and industrialization of certain intellectual work.

Re: Critical vulnerability in LangChain – CVE-2025-68664

#78
post #35

LLM slop. At least one clear error (hallucination): "’Twas the night before Christmas, and I was doing the least festive kind of work: staring at serialization" Per disclosure timeline the report was made on December 4, it was definitely not the night before Christmas when you were doing the work then.

Security research often looks dramatic from the outside. In reality, it is usually the mundane work of asking AI to make up dramatic stories

Re: Critical vulnerability in LangChain – CVE-2025-68664

#79
post #13

Earlier quoted context omitted.

> WHY on earth did the author of the CVE feel the need to feed the description text through an LLm? Not everyone speaks English natively. Not everyone has taste when it comes to written English.

I would rather read succinct English written by a non-native speaker filled with broken grammar than overly verbose but well-spelled AI slop. Heck, just share the prompt itself! If you can't be bothered to have a human write literally a handful of lines of text, what else can't you be bothered to do? Why should I trust that your CVE even exists at all - let alone is indeed "critical" and worth ruining Christmas over?

> Why should I trust that your CVE even exists at all - let alone is indeed "critical" and worth ruining Christmas over?

No reason, of course, the was no Christmas involved:

> Report submitted via Huntr – December 4th, 2025 Acknowledged by LangChain maintainers – December 5th, 2025

Re: Critical vulnerability in LangChain – CVE-2025-68664

#80
post #22

Earlier quoted context omitted.

Yes, framed as you stated it is indeed a win-win. However, there will be cases where lacking the LLM output, there isn't any output at all. Creating a stigma over technology which is easily observed as being, in some form, accessible is expected in the world we live. As it is on HN. Not to say you are being any type of anything, I just don't believe anyone has given it all that much thought. I read the complaints and…

Im sorry but I don't buy the argument that we should be accepting of AI slop because it's more accessible. That type of framing is devious because you frame dissenters as not caring about accessibility. It has nothing to do with accessibility and everything to do with simply not wanting to consume utterly worthless slop.

People generally don't actually care about accessibility and it shows, everywhere. There is obvious and glaring accessibility gains from LLMs that are entirely lost with the stigma.
Post reply on HN