AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Core: ImagePromptValue Cannot Be Deserialized While Sibling Prompt Values Can

ImagePromptValue is marked serializable and dumps() succeeds, but loads() fails because the class is absent from both deserialization allowlists (legacy langchain and langchain_core namespaces) in langchain_core/load/mapping.py. Its three sibling prompt values all round-trip correctly.

mediumConfidence 98%Langchain-CoreAffected V1.6.0

Origin Analysis

The allowlist in langchain_core/load/mapping.py omits ImagePromptValue. StringPromptValue, ChatPromptValue, and ChatPromptValueConcrete are registered in both the legacy ('langchain', ...) namespace block and the current ('langchain_core', ...) block, but ImagePromptValue is missing from both. dumps() uses the legacy id ('langchain', 'schema', 'prompt', 'ImagePromptValue') and loads() with the default allowed_objects='core' rejects it because the mapping entry is absent.
1. Install langchain-core (version 1.6.0 or current master). 2. Run the following Python code: ```python from langchain_core.load import dumps, loads from langchain_core.prompts.image import ImagePromptTemplate template = ImagePromptTemplate( template={"url": "https://example.com/{name}.png"}, input_variables=["name"], ) prompt_value = template.format_prompt(name="cat") print(type(prompt_value).__name__) # ImagePromptValue serialized = dumps(prompt_value) # succeeds loads(serialized) # raises ValueError ``` 3. Observe the ValueError: Deserialization of ('langchain', 'schema', 'prompt', 'ImagePromptValue') is not allowed.

Fixing Code Block

Add the following two entries to langchain_core/load/mapping.py, inside the appropriate allowlist dictionaries: ```python # In the legacy namespace block (keyed by ('langchain', ...)) ("langchain", "schema", "prompt", "ImagePromptValue"): ( "langchain_core", "prompt_values", "ImagePromptValue", ), # In the langchain_core namespace block (keyed by ('langchain_core', ...)) ("langchain_core", "prompt_values", "ImagePromptValue"): ( "langchain_core", "prompt_values", "ImagePromptValue", ), ```
The fix registers ImagePromptValue in both the legacy and current namespace allowlists, mirroring how its sibling prompt value classes are already registered. This ensures that the id emitted by dumps() (legacy namespace) is recognized by loads() with the default allowed_objects='core', restoring round-trip serialization without widening the allowlist or altering public API.

Edge Case Audit

The change is additive and low-risk, but consider the following: (1) The allowlist is a static dictionary; adding entries requires process restart or module reload to take effect in long-running applications. (2) This fix only addresses ImagePromptValue; other serializable classes may still be missing from the allowlist, so a broader audit of all is_lc_serializable() classes is recommended. (3) Be careful when upgrading langchain-core: if the class's namespace or module path changes in future, these mapping entries must be updated synchronously. (4) Do not work around by passing allowed_objects='all' in production, as that disables the safety allowlist entirely. (5) Rollback is straightforward: remove the two added entries; no data migration or compatibility concerns arise. (6) The fix does not introduce concurrency, threading, or cross-platform issues because it only modifies an immutable lookup table.

Ecosystem Topology