PT-2023-29915 · Langchain · Langchain
Published
2023-10-18
·
Updated
2026-03-08
·
CVE-2023-46229
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
LangChain versions prior to 0.0.317
Description
The issue allows Server-Side Request Forgery (SSRF) via the
document loaders/recursive url loader.py module. This occurs because crawling can proceed from an external server to an internal server. The vulnerability is being actively exploited.Recommendations
For versions prior to 0.0.317, update to version 0.0.317 or later to resolve the issue. As a temporary workaround, consider restricting access to the
document loaders/recursive url loader.py module to minimize the risk of exploitation.Fix
RCE
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Langchain