QID 995724

Date Published: 2023-10-26

QID 995724: Python (Pip) Security Update for langchain (GHSA-655w-fm8m-m478)

LangChain before 0.0.317 allows SSRF via document_loaders/recursive_url_loader.py because crawling can proceed from an external server to an internal server.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-655w-fm8m-m478 for updates and patch information.
    Vendor References

    CVEs related to QID 995724

    Software Advisories
    Advisory ID Software Component Link
    GHSA-655w-fm8m-m478 langchain URL Logo github.com/advisories/GHSA-655w-fm8m-m478