Логотип exploitDog
bind:CVE-2026-26013
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-26013

Количество 3

Количество 3

redhat логотип

CVE-2026-26013

около 2 месяцев назад

LangChain is a framework for building agents and LLM-powered applications. Prior to 1.2.11, the ChatOpenAI.get_num_tokens_from_messages() method fetches arbitrary image_url values without validation when computing token counts for vision-enabled models. This allows attackers to trigger Server-Side Request Forgery (SSRF) attacks by providing malicious image URLs in user input. This vulnerability is fixed in 1.2.11.

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2026-26013

около 2 месяцев назад

LangChain is a framework for building agents and LLM-powered applications. Prior to 1.2.11, the ChatOpenAI.get_num_tokens_from_messages() method fetches arbitrary image_url values without validation when computing token counts for vision-enabled models. This allows attackers to trigger Server-Side Request Forgery (SSRF) attacks by providing malicious image URLs in user input. This vulnerability is fixed in 1.2.11.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-2g6r-c272-w58r

около 2 месяцев назад

LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages

CVSS3: 3.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-26013

LangChain is a framework for building agents and LLM-powered applications. Prior to 1.2.11, the ChatOpenAI.get_num_tokens_from_messages() method fetches arbitrary image_url values without validation when computing token counts for vision-enabled models. This allows attackers to trigger Server-Side Request Forgery (SSRF) attacks by providing malicious image URLs in user input. This vulnerability is fixed in 1.2.11.

CVSS3: 3.7
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-26013

LangChain is a framework for building agents and LLM-powered applications. Prior to 1.2.11, the ChatOpenAI.get_num_tokens_from_messages() method fetches arbitrary image_url values without validation when computing token counts for vision-enabled models. This allows attackers to trigger Server-Side Request Forgery (SSRF) attacks by providing malicious image URLs in user input. This vulnerability is fixed in 1.2.11.

CVSS3: 3.7
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2g6r-c272-w58r

LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages

CVSS3: 3.7
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу