2 CVEs affecting @langchain products, 0 known to be exploited (CISA KEV), with EPSS scores. Most affected: MongoDB, Redis.