CVE-2023-46229: LangChain Server Side Request Forgery vulnerability
(updated )
LangChain before 0.0.317 allows SSRF via document_loaders/recursive_url_loader.py
because crawling can proceed from an external server to an internal server.
References
- github.com/advisories/GHSA-655w-fm8m-m478
- github.com/langchain-ai/langchain
- github.com/langchain-ai/langchain/commit/9ecb7240a480720ec9d739b3877a52f76098a2b8
- github.com/langchain-ai/langchain/pull/11925
- github.com/pypa/advisory-database/tree/main/vulns/langchain/PYSEC-2023-205.yaml
- nvd.nist.gov/vuln/detail/CVE-2023-46229
Detect and mitigate CVE-2023-46229 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →