CVE-2023-32786: SSRF
In Langchain through 0.0.155, prompt injection allows an attacker to force the service to retrieve data from an arbitrary URL, essentially providing SSRF and potentially injecting content into downstream tasks.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-32786?
CVE-2023-32786 is a vulnerability in Langchain through version 0.0.155 that allows an attacker to force the service to retrieve data from an arbitrary URL, potentially leading to SSRF and content injection.
How does CVE-2023-32786 work?
CVE-2023-32786 allows an attacker to inject malicious content into downstream tasks by exploiting prompt injection and forcing the service to retrieve data from an arbitrary URL.
What software versions are affected by CVE-2023-32786?
The vulnerability affects Langchain version 0.0.155.
What is the severity of CVE-2023-32786?
The severity of CVE-2023-32786 is not specified.
How can I fix the CVE-2023-32786 vulnerability?
To fix CVE-2023-32786, it is recommended to update Langchain to a version that has fixed the vulnerability.