PT-2024-38931 · Langchain Ai · Langchain-Community+1

Published

2024-10-29

·

Updated

2026-06-15

·

CVE-2024-8309

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: langchain-ai/langchain version 0.2.5 langchain-ai/langchain-community version 0.2.5
Description: A vulnerability in the GraphCypherQAChain class allows for SQL injection through prompt injection, leading to unauthorized data manipulation, data exfiltration, denial of service (DoS) by deleting all data, breaches in multi-tenant security environments, and data integrity issues. Attackers can create, update, or delete nodes and relationships without proper authorization, extract sensitive data, disrupt services, access data across different tenants, and compromise the integrity of the database.
Recommendations: For langchain-ai/langchain version 0.2.5, consider disabling the GraphCypherQAChain class until a patch is available to prevent SQL injection attacks. For langchain-ai/langchain-community version 0.2.5, consider disabling the GraphCypherQAChain class until a patch is available to prevent SQL injection attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-8309
GHSA-45PG-36P6-83V9
PYSEC-2024-115

Affected Products

Langchain
Langchain-Community