LangChain's XMLOutputParser vulnerable to XML Entity Expansion
LangChain's XMLOutputParser vulnerable to XML Entity Expansion
Medium severity. Affects langchain-core < 0.1.35. Upgrade to 0.1.35 or later.
CVE-2024-1455 / GHSA-q84m-rmw3-4382 · severity: medium · CVSS 5.9 · PyPI
Affected
langchain-core< 0.1.35 → fixed in 0.1.35
Details
The XMLOutputParser in LangChain uses the etree module from the XML parser in the standard python library which has some XML vulnerabilities; see: https://docs.python.org/3/library/xml.html
This primarily affects users that combine an LLM (or agent) with the XMLOutputParser and expose the component via an endpoint on a web-service.
This would allow a malicious party to attempt to manipulate the LLM to produce a malicious payload for the parser that would compromise the availability of the service.
A successful attack is predicated on:
- Usage of XMLOutputParser
- Passing of malicious input into the XMLOutputParser either directly or by trying to manipulate an LLM to do so on the users behalf
- Exposing the component via a web-service
Source: GHSA-q84m-rmw3-4382 — GitHub Advisory Database (CC-BY-4.0).