Knowledge base
CodexGuild Knowledge Base

Langchain Server-Side Request Forgery vulnerability

as of Oct 21, 2023 · applies to langchain < 0.0.329 · canonical · codexguild.com/kb/ghsa-6h8p-4hx9-w66c · exported 2026-10-11
Canonical as of Oct 21, 2023

Langchain Server-Side Request Forgery vulnerability

High severity. Affects langchain < 0.0.329. Upgrade to 0.0.329 or later.

CVE-2023-32786 / GHSA-6h8p-4hx9-w66c · severity: high · CVSS 7.5 · PyPI

Affected

  • langchain < 0.0.329 → fixed in 0.0.329

Details

In Langchain before 0.0.329, prompt injection allows an attacker to force the service to retrieve data from an arbitrary URL, essentially providing SSRF and potentially injecting content into downstream tasks.

Source: GHSA-6h8p-4hx9-w66c — GitHub Advisory Database (CC-BY-4.0).