Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-26013

Опубликовано: 10 фев. 2026
Источник: nvd
CVSS3: 3.7
EPSS Низкий

Описание

LangChain is a framework for building agents and LLM-powered applications. Prior to 1.2.11, the ChatOpenAI.get_num_tokens_from_messages() method fetches arbitrary image_url values without validation when computing token counts for vision-enabled models. This allows attackers to trigger Server-Side Request Forgery (SSRF) attacks by providing malicious image URLs in user input. This vulnerability is fixed in 1.2.11.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:langchain:langchain_core:*:*:*:*:*:python:*:*
Версия до 1.2.11 (исключая)

EPSS

Процентиль: 5%
0.00018
Низкий

3.7 Low

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 3.7
redhat
около 2 месяцев назад

LangChain is a framework for building agents and LLM-powered applications. Prior to 1.2.11, the ChatOpenAI.get_num_tokens_from_messages() method fetches arbitrary image_url values without validation when computing token counts for vision-enabled models. This allows attackers to trigger Server-Side Request Forgery (SSRF) attacks by providing malicious image URLs in user input. This vulnerability is fixed in 1.2.11.

CVSS3: 3.7
github
около 1 месяца назад

LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages

EPSS

Процентиль: 5%
0.00018
Низкий

3.7 Low

CVSS3

Дефекты

CWE-918