PT-2023-29915 · Langchain · Langchain

Publicado

2023-10-18

·

Atualizado

2026-03-08

·

CVE-2023-46229

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LangChain versions prior to 0.0.317
Description The issue allows Server-Side Request Forgery (SSRF) via the document loaders/recursive url loader.py module. This occurs because crawling can proceed from an external server to an internal server. The vulnerability is being actively exploited.
Recommendations For versions prior to 0.0.317, update to version 0.0.317 or later to resolve the issue. As a temporary workaround, consider restricting access to the document loaders/recursive url loader.py module to minimize the risk of exploitation.

Correção

RCE

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-46229
GHSA-655W-FM8M-M478
PYSEC-2023-205

Produtos afetados

Langchain