PT-2023-24019 · Langchain · Langchain

·

CVE-2023-32786

·

Publicado

2023-10-20

·

Atualizado

2026-07-07

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Langchain versions 0.0.0 through 0.0.155 Langchain versions prior to 0.0.329
Description The issue allows an attacker to force the service to retrieve data from an arbitrary URL, essentially providing Server-Side Request Forgery (SSRF) and potentially injecting content into downstream tasks. This is achieved through prompt injection.
Recommendations For versions 0.0.0 through 0.0.155, update to version 0.0.329 or later. For versions prior to 0.0.329, update to version 0.0.329 or later. As a temporary workaround, consider restricting the ability to inject prompts that force the service to retrieve data from arbitrary URLs until a patch is available.

Exploit

Correção

SSRF

Special Elements Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-32786
GHSA-6H8P-4HX9-W66C
PYSEC-2026-1508

Produtos afetados

Langchain