PT-2023-24018 · Langchain · Langchain

Published

2023-10-20

·

Updated

2023-12-26

·

CVE-2023-32785

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Langchain versions 0.0.155 and earlier Langchain versions prior to 0.0.247
Description The issue allows for prompt injection, enabling the execution of arbitrary code against the SQL service provided by the chain.
Recommendations For Langchain versions 0.0.155 and earlier, update to version 0.0.247 or later to resolve the issue. For Langchain versions prior to 0.0.247, update to version 0.0.247 or later to resolve the issue.

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2023-32785
GHSA-8H5W-F6Q9-WG35

Affected Products

Langchain