AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

PromptTemplate Silently Accepts Empty F-String Field `{}` Then Crashes With IndexError On Format

PromptTemplate.from_template("Value: {}") is accepted silently, reports an empty input variable, and then raises IndexError on every .format() call. It should be rejected at creation time with a clear ValueError, consistent with the all-digit `{0}` case.

mediumConfidence 95%LangChainAffected V1.6.3

Origin Analysis

The f-string validation in langchain_core.prompts.string only checks for all-digit variable names. An empty replacement field `{}` becomes a variable named `''`, which passes the all-digit check because an empty string is not all digits. Later, Python's string.Formatter interprets `{}` as an auto-numbered positional field and calls get_value with key `''`, but the positional args tuple contains no matching element, causing IndexError.
```python from langchain_core.prompts import PromptTemplate t = PromptTemplate.from_template("Value: {}") print(t.input_variables) # [''] t.format() # IndexError: tuple index out of range t.format(**{"": "x"}) # IndexError: tuple index out of range ```

Fixing Code Block

def validate_f_string_template(template: str, *, allowed_input_variables: list[str] | None = None) -> set[str]: """Validate f-string template variables.""" try: variables = get_template_variables(template, "f-string") except ValueError as e: raise ValueError(f"Invalid f-string: {e}") from e for variable in variables: if variable == "": raise ValueError( "Variable names cannot be empty. Use '{{}}' to escape literal braces." ) if variable.isdigit(): raise ValueError( "Variable names cannot be all digits; they are interpreted as positional arguments." ) if allowed_input_variables is not None: undefined = variables - set(allowed_input_variables) if undefined: raise ValueError( f"Undefined variables: {sorted(undefined)}" ) return variables
After extracting variables from the f-string template, the function now rejects any variable whose name is an empty string, raising a clear ValueError at template creation time. This prevents the invalid `{}` from being stored and later crashing with an opaque IndexError. The existing all-digit check is retained.

Edge Case Audit

This fix changes behavior for templates containing `{}`. Previously they were accepted and only failed when formatting was attempted; after the fix they raise ValueError during PromptTemplate.from_template(). This is the intended safe behavior, but any application that intentionally created such templates (however unlikely) will break. To rollback, revert to the previous function or temporarily remove the empty-string check. Users who need literal braces should escape them as `{{}}`. The validation is pure and has no concurrency or threading implications. Apply this patch to langchain-core 1.6.3 and current master after running existing prompt tests.

Ecosystem Topology