SOURCE-LINKED INTELLIGENCE
GHSA-6h8p-4hx9-w66c: Langchain Server-Side Request Forgery vulnerability
In Langchain before 0.0.329, prompt injection allows an attacker to force the service to retrieve data from an arbitrary URL, essentially providing SSRF and potentially injecting content into downstream tasks.
Read original source ↗ Open in workspace
- recordType
- vulnerability
- status
- active
- evidenceStatus
- reported
- region
- Global
Evidence & attribution
- OSV AI package advisories · 2023-10-21T00:30:47.000Z
- OSV AI package advisories · 2026-07-07T11:45:26.029Z
First collected: 2026-09-19T20:26:55.867Z. This is not the publication date.