QID 995709

Date Published: 2023-10-25

QID 995709: Python (Pip) Security Update for langchain (GHSA-6h8p-4hx9-w66c)

In Langchain through 0.0.155, prompt injection allows an attacker to force the service to retrieve data from an arbitrary URL, essentially providing SSRF and potentially injecting content into downstream tasks.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Refer to Github security advisory GHSA-6h8p-4hx9-w66c for updates and patch information.
    Vendor References

    CVEs related to QID 995709

    Software Advisories
    Advisory ID Software Component Link