AI Security Vulnerability
LangChain before 0.0.317 allows SSRF via `document_loaders/recursive_url_loader.py` because crawling can proceed from an external server to an internal server.
What Happened
LangChain before 0.0.317 allows SSRF via `document_loaders/recursive_url_loader.py` because crawling can proceed from an external server to an internal server.
Why This Matters
Current evidence identifies a security issue involving the affected technology, but does not yet support a more specific impact claim.
Recommended Action
No confirmed vendor remediation is available in the current evidence. Confirm whether the affected technology is present in your environment and review the affected configuration.
Exposure
Exposure unknown
Oct 19, 2023 12:00
Exposure reason: This incident does not currently match a technology in My Interests.
Exploitation status: UNKNOWN
Primary entities:
Timeline
-
Incident first seen
Oct 19, 2023 12:00BugSkan first recorded this incident.
-
LangChain Server Side Request Forgery vulnerability
Oct 19, 2023 12:00GitHub Advisory Database · Research
Sources
GitHub Advisory Database · Oct 19, 2023 12:00
LangChain before 0.0.317 allows SSRF via `document_loaders/recursive_url_loader.py` because crawling can proceed from an external server to an internal server.
Open publisher sourceMy Interests Match
Create an account to see which incidents overlap with your interests.