Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pc6w-59fv-rh23

Опубликовано: 04 сент. 2025
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Langchain Community Vulnerable to XML External Entity (XXE) Attacks

The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The vulnerability arises from the use of etree.iterparse() without disabling external entity references, which can lead to sensitive information disclosure. An attacker could exploit this by crafting a malicious XML payload that references local files, potentially exposing sensitive data such as /etc/passwd. This issue has been fixed in 0.3.27 of langchain-community.

Пакеты

Наименование

langchain-community

pip
Затронутые версииВерсия исправления

< 0.3.27

0.3.27

EPSS

Процентиль: 5%
0.00021
Низкий

7.5 High

CVSS3

Дефекты

CWE-200
CWE-611

Связанные уязвимости

CVSS3: 7.5
redhat
5 месяцев назад

The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The affected version is 0.3.63. The vulnerability arises from the use of etree.iterparse() without disabling external entity references, which can lead to sensitive information disclosure. An attacker could exploit this by crafting a malicious XML payload that references local files, potentially exposing sensitive data such as /etc/passwd.

CVSS3: 7.5
nvd
5 месяцев назад

The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The affected version is 0.3.63. The vulnerability arises from the use of etree.iterparse() without disabling external entity references, which can lead to sensitive information disclosure. An attacker could exploit this by crafting a malicious XML payload that references local files, potentially exposing sensitive data such as /etc/passwd.

EPSS

Процентиль: 5%
0.00021
Низкий

7.5 High

CVSS3

Дефекты

CWE-200
CWE-611