Vulnerability Description
LangChain before 0.0.317 allows SSRF via document_loaders/recursive_url_loader.py because crawling can proceed from an external server to an internal server.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Langchain | Langchain | < 0.0.317 |
Related Weaknesses (CWE)
References
- https://github.com/langchain-ai/langchain/commit/9ecb7240a480720ec9d739b3877a52fPatch
- https://github.com/langchain-ai/langchain/pull/11925PatchVendor Advisory
- https://github.com/langchain-ai/langchain/commit/9ecb7240a480720ec9d739b3877a52fPatch
- https://github.com/langchain-ai/langchain/pull/11925PatchVendor Advisory
FAQ
What is CVE-2023-46229?
CVE-2023-46229 is a vulnerability with a CVSS score of 8.8 (HIGH). LangChain before 0.0.317 allows SSRF via document_loaders/recursive_url_loader.py because crawling can proceed from an external server to an internal server.
How severe is CVE-2023-46229?
CVE-2023-46229 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-46229?
Check the references section above for vendor advisories and patch information. Affected products include: Langchain Langchain.