Skip to content
LangChainPYSEC-2024-278

A vulnerability was found in LangChain langchain_community 0.0.26. It has been classified as critical. Affected is the function load_local in the library libs/community/langchain_community/retrievers/tfidf.py of the component TFIDFRetriever. The manipulation leads to server-side request forgery. It

Critical9.8CVE-2024-2057 · Published Mar 1, 2024 · updated May 21, 2026

Source advisory

Affected versions

PackageAffectedFixed in
langchain-community
PyPI
<= 0.0.26No fix yet
Details and references

A vulnerability was found in LangChain langchain_community 0.0.26. It has been classified as critical. Affected is the function load_local in the library libs/community/langchain_community/retrievers/tfidf.py of the component TFIDFRetriever. The manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 0.0.27 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-255372.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
the CVSS score
Also known as
CVE-2024-2057

More LangChain advisories

All LangChain
DateAdvisory
Mar 42024LangChain directory traversal vulnerability
CVE-2024-28088Lowfixed in 0.0.339, 0.1.30
Feb 262024LangChain Experimental vulnerable to arbitrary code execution
CVE-2024-27444Critical9.8fixed in 0.0.52
Feb 262024langchain Server-Side Request Forgery vulnerability
CVE-2024-0243Low3.7fixed in 0.1.0
Mar 262024LangChain's XMLOutputParser vulnerable to XML Entity Expansion
CVE-2024-1455Medium5.9fixed in 0.1.35
Apr 162024langchain vulnerable to path traversal
CVE-2024-3571Medium6.5fixed in 0.0.353
Jun 62024Denial of service in langchain-community
CVE-2024-2965Medium4.2fixed in 0.2.5

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.