HIGH 8.8 PyPI
LangChain Server Side Request Forgery vulnerability
GHSA-655w-fm8m-m478 · CVE-2023-46229 · PYSEC-2023-205
Published · Modified
Description
LangChain before 0.0.317 allows SSRF via document_loaders/recursive_url_loader.py because crawling can proceed from an external server to an internal server.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2023-46229
- WEB https://github.com/langchain-ai/langchain/pull/11925
- WEB https://github.com/langchain-ai/langchain/commit/9ecb7240a480720ec9d739b3877a52f76098a2b8
- PACKAGE https://github.com/langchain-ai/langchain
- WEB https://github.com/pypa/advisory-database/tree/main/vulns/langchain/PYSEC-2023-205.yaml
Ready to move
Start Securing
Free, no credit card | First findings in minutes