Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 PyPI

Langchain Server-Side Request Forgery vulnerability

GHSA-6h8p-4hx9-w66c · CVE-2023-32786

Published · Modified

Description

In Langchain before 0.0.329, prompt injection allows an attacker to force the service to retrieve data from an arbitrary URL, essentially providing SSRF and potentially injecting content into downstream tasks.

Ready to move

Start Securing

Free, no credit card | First findings in minutes