In Langchain through 0.0.155, prompt injection allows an attacker to force the service to retrieve data from an arbitrary URL, essentially providing SSRF and potentially injecting content into downstream tasks.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-2674 In Langchain through 0.0.155, prompt injection allows an attacker to force the service to retrieve data from an arbitrary URL, essentially providing SSRF and potentially injecting content into downstream tasks.
Github GHSA Github GHSA GHSA-6h8p-4hx9-w66c Langchain Server-Side Request Forgery vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-09-12T17:54:54.643Z

Reserved: 2023-05-15T00:00:00

Link: CVE-2023-32786

cve-icon Vulnrichment

Updated: 2024-08-02T15:25:37.167Z

cve-icon NVD

Status : Modified

Published: 2023-10-20T22:15:10.553

Modified: 2024-11-21T08:04:01.443

Link: CVE-2023-32786

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.