LangChainGHSA-6h8p-4hx9-w66c
Langchain Server-Side Request Forgery vulnerability
High7.5CVE-2023-32786 · Published Oct 21, 2023 · updated Jul 7, 2026
In Langchain before 0.0.329, prompt injection allows an attacker to force the service to retrieve data from an arbitrary URL, essentially providing SSRF and potentially injecting content into downstream tasks.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| langchain PyPI | < 0.0.329 | 0.0.329 |
Details and references
More LangChain advisories
All LangChain| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 212023 | Langchain SQL Injection vulnerability | Critical9.8 | 0.0.247 |
| Oct 192023 | LangChain Server Side Request Forgery vulnerability | High8.8 | 0.0.317 |
| Oct 92023 | langchain_experimental vulnerable to arbitrary code execution via PALChain in the python exec method | Critical9.8 | No fix yet |
| Sep 12023 | Langchain vulnerable to arbitrary code execution via the evaluate function in the numexpr library | Critical9.8 | 0.0.308 |
| Aug 222023 | langchain vulnerable to arbitrary code execution | Critical9.8 | 0.0.312 |
| Aug 152023 | LangChain vulnerable to arbitrary code execution | Critical9.8 | 0.0.236 |