HIGH 8.8 PyPI

LangChain Server Side Request Forgery vulnerability

GHSA-655w-fm8m-m478 · CVE-2023-46229 · PYSEC-2023-205

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

LangChain before 0.0.317 allows SSRF via document_loaders/recursive_url_loader.py because crawling can proceed from an external server to an internal server.

Ready to move

Start Securing

Free, no credit card | First findings in minutes