PT-2023-29915 · Langchain · Langchain

Published

2023-10-18

·

Updated

2026-03-08

·

CVE-2023-46229

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LangChain versions prior to 0.0.317
Description The issue allows Server-Side Request Forgery (SSRF) via the document loaders/recursive url loader.py module. This occurs because crawling can proceed from an external server to an internal server. The vulnerability is being actively exploited.
Recommendations For versions prior to 0.0.317, update to version 0.0.317 or later to resolve the issue. As a temporary workaround, consider restricting access to the document loaders/recursive url loader.py module to minimize the risk of exploitation.

Fix

RCE

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-46229
GHSA-655W-FM8M-M478
PYSEC-2023-205

Affected Products

Langchain