LangChain Server Side Request Forgery vulnerability
High severity
GitHub Reviewed
Published
Oct 19, 2023
to the GitHub Advisory Database
•
Updated Sep 30, 2024
Description
Published by the National Vulnerability Database
Oct 19, 2023
Published to the GitHub Advisory Database
Oct 19, 2023
Reviewed
Oct 19, 2023
Last updated
Sep 30, 2024
LangChain before 0.0.317 allows SSRF via
document_loaders/recursive_url_loader.py
because crawling can proceed from an external server to an internal server.References