Логотип exploitDog
bind:CVE-2025-6984
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-6984

Количество 3

Количество 3

redhat логотип

CVE-2025-6984

5 месяцев назад

The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The affected version is 0.3.63. The vulnerability arises from the use of etree.iterparse() without disabling external entity references, which can lead to sensitive information disclosure. An attacker could exploit this by crafting a malicious XML payload that references local files, potentially exposing sensitive data such as /etc/passwd.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2025-6984

5 месяцев назад

The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The affected version is 0.3.63. The vulnerability arises from the use of etree.iterparse() without disabling external entity references, which can lead to sensitive information disclosure. An attacker could exploit this by crafting a malicious XML payload that references local files, potentially exposing sensitive data such as /etc/passwd.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-pc6w-59fv-rh23

5 месяцев назад

Langchain Community Vulnerable to XML External Entity (XXE) Attacks

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2025-6984

The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The affected version is 0.3.63. The vulnerability arises from the use of etree.iterparse() without disabling external entity references, which can lead to sensitive information disclosure. An attacker could exploit this by crafting a malicious XML payload that references local files, potentially exposing sensitive data such as /etc/passwd.

CVSS3: 7.5
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2025-6984

The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The affected version is 0.3.63. The vulnerability arises from the use of etree.iterparse() without disabling external entity references, which can lead to sensitive information disclosure. An attacker could exploit this by crafting a malicious XML payload that references local files, potentially exposing sensitive data such as /etc/passwd.

CVSS3: 7.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-pc6w-59fv-rh23

Langchain Community Vulnerable to XML External Entity (XXE) Attacks

CVSS3: 7.5
0%
Низкий
5 месяцев назад

Уязвимостей на страницу