Skip to content
LangChainGHSA-q25c-c977-4cmh

Server-Side Request Forgery in langchain-community.retrievers.web_research.WebResearchRetriever

Medium4.8CVE-2024-3095 · Published Jun 6, 2024 · updated Jul 7, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
langchain-community
PyPI
< 0.2.90.2.9
Details and references

A Server-Side Request Forgery (SSRF) vulnerability exists in the Web Research Retriever component in langchain-community (langchain-community.retrievers.web_research.WebResearchRetriever). The vulnerability arises because the Web Research Retriever does not restrict requests to remote internet addresses, allowing it to reach local addresses. This flaw enables attackers to execute port scans, access local services, and in some scenarios, read instance metadata from cloud environments. The vulnerability is particularly concerning as it can be exploited to abuse the Web Explorer server as a proxy for web attacks on third parties and interact with servers in the local network, including reading their response data. This could potentially lead to arbitrary code execution, depending on the nature of the local services. The vulnerability is limited to GET requests, as POST requests are not possible, but the impact on confidentiality, integrity, and availability is significant due to the potential for stolen credentials and state-changing interactions with internal APIs. The patched code: * Requires users to opt-in * Suggests using a proxy to prevent requests to local addresses

CVSS 3.0
CVSS:3.0/AV:P/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-918
Also known as
CVE-2024-3095, PYSEC-2026-1516

More LangChain advisories

All LangChain
DateAdvisory
Jun 62024Denial of service in langchain-community
CVE-2024-2965Medium4.2fixed in 0.2.5
Jun 162024langchain_experimental Code Execution via Python REPL access
CVE-2024-38459High7.8fixed in 0.0.61
Jul 152024langchain-experimental vulnerable to Arbitrary Code Execution
CVE-2024-21513Critical8.5fixed in 0.0.21
Apr 162024langchain vulnerable to path traversal
CVE-2024-3571Medium6.5fixed in 0.0.353
Mar 262024LangChain's XMLOutputParser vulnerable to XML Entity Expansion
CVE-2024-1455Medium5.9fixed in 0.1.35
Mar 42024LangChain directory traversal vulnerability
CVE-2024-28088Lowfixed in 0.0.339, 0.1.30

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.