Логотип exploitDog
bind:CVE-2025-9556
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-9556

Количество 2

Количество 2

nvd логотип

CVE-2025-9556

5 месяцев назад

Langchaingo supports the use of jinja2 syntax when parsing prompts, which is in turn parsed using the gonja library v1.5.3. Gonja supports include and extends syntax to read files, which leads to a server side template injection vulnerability within langchaingo, allowing an attacker to insert a statement into a prompt to read the "etc/passwd" file.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-v6f2-g4gw-r4rc

5 месяцев назад

Langchaingo supports the use of jinja2 syntax when parsing prompts, which is in turn parsed using the gonja library v1.5.3. Gonja supports include and extends syntax to read files, which leads to a server side template injection vulnerability within langchaingo, allowing an attacker to insert a statement into a prompt to read the "etc/passwd" file.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-9556

Langchaingo supports the use of jinja2 syntax when parsing prompts, which is in turn parsed using the gonja library v1.5.3. Gonja supports include and extends syntax to read files, which leads to a server side template injection vulnerability within langchaingo, allowing an attacker to insert a statement into a prompt to read the "etc/passwd" file.

CVSS3: 9.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-v6f2-g4gw-r4rc

Langchaingo supports the use of jinja2 syntax when parsing prompts, which is in turn parsed using the gonja library v1.5.3. Gonja supports include and extends syntax to read files, which leads to a server side template injection vulnerability within langchaingo, allowing an attacker to insert a statement into a prompt to read the "etc/passwd" file.

CVSS3: 9.8
0%
Низкий
5 месяцев назад

Уязвимостей на страницу