LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates
Attackers who can control template strings (not just template variables) can: Access Python object attributes and internal properties via attribute traversal Extract sensitive information from object internals (e.g., class, globals) Potentially escalate to more severe attacks depending on the objects passed to templates