Skip to content
LangChainGHSA-h5gc-rm8j-5gpr

LangChain Community SSRF vulnerability exists in RequestsToolkit component

High8.4CVE-2025-2828 · Published Jun 23, 2025 · updated Jul 17, 2025

GitHub advisory

Affected versions

PackageAffectedFixed in
langchain-community
PyPI
< 0.0.280.0.28
Details and references

A Server-Side Request Forgery (SSRF) vulnerability exists in the RequestsToolkit component of the langchain-community package (specifically, langchain_community.agent_toolkits.openapi.toolkit.RequestsToolkit) in langchain-ai/langchain version 0.0.27. This vulnerability occurs because the toolkit does not enforce restrictions on requests to remote internet addresses, allowing it to also access local addresses. As a result, an attacker could exploit this flaw to perform port scans, access local services, retrieve instance metadata from cloud environments (e.g., Azure, AWS), and interact with servers on the local network. This issue has been fixed in version 0.0.28.

CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-918
Also known as
CVE-2025-2828, PYSEC-2025-70

More LangChain advisories

All LangChain
DateAdvisory
Sep 42025Langchain Community Vulnerable to XML External Entity (XXE) Attacks
CVE-2025-6984High7.5fixed in 0.3.27
Mar 202025langchain-core allows unauthorized users to read arbitrary files from the host file system
CVE-2024-10940Medium5.3fixed in 0.1.53, 0.2.43, 0.3.15
Nov 202025LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates
CVE-2025-65106Highfixed in 0.3.80, 1.0.7
Dec 232025LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs
CVE-2025-68664Critical9.3fixed in 0.3.81, 1.2.5
Dec 232025LangChain serialization injection vulnerability enables secret extraction
CVE-2025-68665High8.6fixed in 0.3.37, 0.3.80, 1.1.8, 1.2.3
Feb 11LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages
CVE-2026-26013Low3.7fixed in 1.2.11

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.