CodexGuild Knowledge Base
Langchain SQL Injection vulnerability
Canonical as of Oct 21, 2023
Langchain SQL Injection vulnerability
Critical severity. Affects langchain < 0.0.247. Upgrade to 0.0.247 or later.
CVE-2023-32785 / GHSA-8h5w-f6q9-wg35 · severity: critical · CVSS 9.8 · PyPI
Affected
langchain< 0.0.247 → fixed in 0.0.247
Details
In Langchain before 0.0.247, prompt injection allows execution of arbitrary code against the SQL service provided by the chain.
Source: GHSA-8h5w-f6q9-wg35 — GitHub Advisory Database (CC-BY-4.0).