CodexGuild Knowledge Base
Langchain Server-Side Request Forgery vulnerability
Canonical as of Oct 21, 2023
Langchain Server-Side Request Forgery vulnerability
High severity. Affects langchain < 0.0.329. Upgrade to 0.0.329 or later.
CVE-2023-32786 / GHSA-6h8p-4hx9-w66c · severity: high · CVSS 7.5 · PyPI
Affected
langchain< 0.0.329 → fixed in 0.0.329
Details
In Langchain before 0.0.329, prompt injection allows an attacker to force the service to retrieve data from an arbitrary URL, essentially providing SSRF and potentially injecting content into downstream tasks.
Source: GHSA-6h8p-4hx9-w66c — GitHub Advisory Database (CC-BY-4.0).