Описание
Langchain Server-Side Request Forgery vulnerability
In Langchain before 0.0.329, prompt injection allows an attacker to force the service to retrieve data from an arbitrary URL, essentially providing SSRF and potentially injecting content into downstream tasks.
Пакеты
Наименование
langchain
pip
Затронутые версииВерсия исправления
< 0.0.329
0.0.329
Связанные уязвимости
CVSS3: 7.5
nvd
больше 2 лет назад
In Langchain through 0.0.155, prompt injection allows an attacker to force the service to retrieve data from an arbitrary URL, essentially providing SSRF and potentially injecting content into downstream tasks.