AIIC AI Intelligence Centre

SOURCE-LINKED INTELLIGENCE

GHSA-6h8p-4hx9-w66c: Langchain Server-Side Request Forgery vulnerability

OSV AI package advisories · observation · Oct 21, 2023 · UTC

In Langchain before 0.0.329, prompt injection allows an attacker to force the service to retrieve data from an arbitrary URL, essentially providing SSRF and potentially injecting content into downstream tasks.

Read original source ↗ Open in workspace

recordType
vulnerability
status
active
evidenceStatus
reported
region
Global

Evidence & attribution

First collected: 2026-09-19T20:26:55.867Z. This is not the publication date.