AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Core: Create_image_block Does Not Enforce The Mime_type Requirement Its Docstring Declares

`create_image_block` in langchain-core accepts base64 data without a `mime_type`, unlike its siblings `create_video_block`, `create_audio_block`, and `create_file_block`. This produces blocks that cannot be converted to valid provider payloads and violates the function's documented contract.

mediumConfidence 95%LangchainAffected V1.6.0

Origin Analysis

The `create_image_block` function in `langchain_core/messages/content.py` performs the source presence check (`url`, `base64`, or `file_id`) but omits the `if base64 and not mime_type: raise ValueError` guard present in the other three factory functions. This allows construction of an `ImageContentBlock` with base64 data and no MIME type, leading to malformed data URLs downstream.
```python from langchain_core.messages.content import create_image_block # Expected ValueError, but returns a block without mime_type block = create_image_block(base64="aGk=") print(block) ``` Observed output: `{'type': 'image', 'id': 'lc_...', 'base64': 'aGk='}`

Fixing Code Block

def create_image_block( *, url: str | None = None, base64: str | None = None, file_id: str | None = None, mime_type: str | None = None, id: str | None = None, ) -> ImageContentBlock: if not any([url, base64, file_id]): msg = "Must provide one of: url, base64, or file_id" raise ValueError(msg) if base64 and not mime_type: msg = "mime_type is required when using base64 data" raise ValueError(msg) block = ImageContentBlock(type="image", id=ensure_id(id)) if url is not None: block["url"] = url if base64 is not None: block["base64"] = base64 if mime_type is not None: block["mime_type"] = mime_type if file_id is not None: block["file_id"] = file_id return block
Adds the same validation guard used by `create_video_block`, `create_audio_block`, and `create_file_block`. When `base64` is provided without `mime_type`, the function now raises a `ValueError` with a clear message, aligning behavior with the documented contract and preventing construction of invalid blocks.

Edge Case Audit

This is a potentially breaking change for existing code that calls `create_image_block(base64=...)` without a `mime_type`. After upgrading, such calls will raise `ValueError`. Mitigation: update call sites to provide an explicit `mime_type` or pin `langchain-core` to a version before this fix if the lenient behavior is required. The change is synchronous and does not introduce threading or async issues. Rollback: remove the added guard or revert to the previous version. Providers will now receive valid data URLs instead of `data:None;base64,...`.

Ecosystem Topology