PT-2023-29915 · Langchain · Langchain
Publicado
2023-10-18
·
Atualizado
2026-03-08
·
CVE-2023-46229
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
LangChain versions prior to 0.0.317
Description
The issue allows Server-Side Request Forgery (SSRF) via the
document loaders/recursive url loader.py module. This occurs because crawling can proceed from an external server to an internal server. The vulnerability is being actively exploited.Recommendations
For versions prior to 0.0.317, update to version 0.0.317 or later to resolve the issue. As a temporary workaround, consider restricting access to the
document loaders/recursive url loader.py module to minimize the risk of exploitation.Correção
RCE
SSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Langchain