LangChain before 0.0.317 allows SSRF via document_loaders/recursive_url_loader.py because crawling can proceed from an external server to an internal server.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-0119 LangChain before 0.0.317 allows SSRF via document_loaders/recursive_url_loader.py because crawling can proceed from an external server to an internal server.
Github GHSA Github GHSA GHSA-655w-fm8m-m478 LangChain Server Side Request Forgery vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-09-12T18:06:21.757Z

Reserved: 2023-10-19T00:00:00

Link: CVE-2023-46229

cve-icon Vulnrichment

Updated: 2024-08-02T20:37:40.240Z

cve-icon NVD

Status : Modified

Published: 2023-10-19T05:15:58.737

Modified: 2024-11-21T08:28:07.320

Link: CVE-2023-46229

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses