CVE-2023-32786High· 7.5▾ TwilightLangchain Server-Side Request Forgery vulnerability
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.6%
0.6% → 0.7%
In Langchain before 0.0.329, prompt injection allows an attacker to force the service to retrieve data from an arbitrary URL, essentially providing SSRF and potentially injecting content into downstream tasks.
langchain < 0.0.329Upgrade to a patched release:
langchain 0.0.329Connected by shared product, vendor, weakness, or advisory.
CVE-2024-3571Medium· 6.5langchain vulnerable to path traversal
CVE-2024-0243Low· 3.7langchain Server-Side Request Forgery vulnerability
CVE-2026-55443Medium· 5.1LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders
CVE-2023-36188Critical· 9.8langchain vulnerable to arbitrary code execution
CVE-2026-34070High· 7.5LangChain is a framework for building agents and LLM-powered applications
GHSA-gr75-jv2w-4656Medium· 5.1LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders