LangChainGHSA-8h5w-f6q9-wg35
Langchain SQL Injection vulnerability
Critical9.8CVE-2023-32785 · Published Oct 21, 2023 · updated Jun 29, 2026
In Langchain before 0.0.247, prompt injection allows execution of arbitrary code against the SQL service provided by the chain.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| langchain PyPI | < 0.0.247 | 0.0.247 |
Details and references
More LangChain advisories
All LangChain| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 212023 | Langchain Server-Side Request Forgery vulnerability | High7.5 | 0.0.329 |
| Oct 192023 | LangChain Server Side Request Forgery vulnerability | High8.8 | 0.0.317 |
| Oct 92023 | langchain_experimental vulnerable to arbitrary code execution via PALChain in the python exec method | Critical9.8 | No fix yet |
| Sep 12023 | Langchain vulnerable to arbitrary code execution via the evaluate function in the numexpr library | Critical9.8 | 0.0.308 |
| Aug 222023 | langchain vulnerable to arbitrary code execution | Critical9.8 | 0.0.312 |
| Aug 152023 | LangChain vulnerable to arbitrary code execution | Critical9.8 | 0.0.236 |