PT-2023-24018 · Langchain · Langchain

CVE-2023-32785

·

Publicado

2023-10-20

·

Atualizado

2026-06-29

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Langchain versions 0.0.155 and earlier Langchain versions prior to 0.0.247
Description The issue allows for prompt injection, enabling the execution of arbitrary code against the SQL service provided by the chain.
Recommendations For Langchain versions 0.0.155 and earlier, update to version 0.0.247 or later to resolve the issue. For Langchain versions prior to 0.0.247, update to version 0.0.247 or later to resolve the issue.

Correção

Special Elements Injection

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-32785
GHSA-8H5W-F6Q9-WG35
PYSEC-2026-372

Produtos afetados

Langchain