logo

Database

Server-side request forgery (SSRF) In langchain

Description

LangChain Server Side Request Forgery vulnerability LangChain before 0.0.317 allows SSRF via document_loaders/recursive_url_loader.py because crawling can proceed from an external server to an internal server.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions
FLAT-AQ06P – Vulnerability | Fluid Attacks Database