PT-2023-24018 · Langchain · Langchain
Published
2023-10-20
·
Updated
2023-12-26
·
CVE-2023-32785
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Langchain versions 0.0.155 and earlier
Langchain versions prior to 0.0.247
Description
The issue allows for prompt injection, enabling the execution of arbitrary code against the SQL service provided by the chain.
Recommendations
For Langchain versions 0.0.155 and earlier, update to version 0.0.247 or later to resolve the issue.
For Langchain versions prior to 0.0.247, update to version 0.0.247 or later to resolve the issue.
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Langchain