Skip to content
LangChainGHSA-655w-fm8m-m478

LangChain Server Side Request Forgery vulnerability

High8.8CVE-2023-46229 · Published Oct 19, 2023 · updated Sep 30, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
langchain
PyPI
< 0.0.3170.0.317
Details and references

LangChain before 0.0.317 allows SSRF via `document_loaders/recursive_url_loader.py` because crawling can proceed from an external server to an internal server.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-918
Also known as
CVE-2023-46229, PYSEC-2023-205

More LangChain advisories

All LangChain
DateAdvisory
Oct 212023Langchain Server-Side Request Forgery vulnerability
CVE-2023-32786High7.5fixed in 0.0.329
Oct 212023Langchain SQL Injection vulnerability
CVE-2023-32785Critical9.8fixed in 0.0.247
Oct 92023langchain_experimental vulnerable to arbitrary code execution via PALChain in the python exec method
CVE-2023-44467Critical9.8no fix yet
Sep 12023Langchain vulnerable to arbitrary code execution via the evaluate function in the numexpr library
CVE-2023-39631Critical9.8fixed in 0.0.308
Aug 222023langchain vulnerable to arbitrary code execution
CVE-2023-36281Critical9.8fixed in 0.0.312
Aug 152023LangChain vulnerable to arbitrary code execution
CVE-2023-38896Critical9.8fixed in 0.0.236

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.