Launch Week Day 1: Announcing Security Design Review
HIGH 8.8 PyPI

LangChain Server Side Request Forgery vulnerability

GHSA-655w-fm8m-m478 · CVE-2023-46229 · PYSEC-2023-205

Published · Modified

Description

LangChain before 0.0.317 allows SSRF via document_loaders/recursive_url_loader.py because crawling can proceed from an external server to an internal server.

Ready to move

Start Securing

Free, no credit card | First findings in minutes