Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-18953 | LangChain Community SSRF vulnerability exists in RequestsToolkit component |
Github GHSA |
GHSA-h5gc-rm8j-5gpr | LangChain Community SSRF vulnerability exists in RequestsToolkit component |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 16 Jul 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Langchain
Langchain langchain |
|
| CPEs | cpe:2.3:a:langchain:langchain:*:*:*:*:community:*:*:* | |
| Vendors & Products |
Langchain
Langchain langchain |
|
| Metrics |
cvssV3_1
|
Tue, 24 Jun 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 24 Jun 2025 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 23 Jun 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Server-Side Request Forgery (SSRF) vulnerability exists in the RequestsToolkit component of the langchain-community package (specifically, langchain_community.agent_toolkits.openapi.toolkit.RequestsToolkit) in langchain-ai/langchain version 0.0.27. This vulnerability occurs because the toolkit does not enforce restrictions on requests to remote internet addresses, allowing it to also access local addresses. As a result, an attacker could exploit this flaw to perform port scans, access local services, retrieve instance metadata from cloud environments (e.g., Azure, AWS), and interact with servers on the local network. This issue has been fixed in version 0.0.28. | |
| Title | SSRF Vulnerability in RequestsToolkit in langchain-ai/langchain | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2025-06-24T13:32:19.925Z
Reserved: 2025-03-26T17:46:45.448Z
Link: CVE-2025-2828
Updated: 2025-06-24T13:32:09.715Z
Status : Analyzed
Published: 2025-06-23T21:15:25.210
Modified: 2025-07-16T19:46:41.933
Link: CVE-2025-2828
OpenCVE Enrichment
Updated: 2025-06-27T14:10:58Z
EUVD
Github GHSA