Low
osv
ยท
GHSA-6h8p-4hx9-w66c
Langchain Server-Side Request Forgery vulnerability
Published Oct 21, 2023
CVSS 3.1
In Langchain before 0.0.329, prompt injection allows an attacker to force the service to retrieve data from an arbitrary URL, essentially providing SSRF and potentially injecting content into downstream tasks.
Affected AI Products
langchain