---
id: CVE-2024-0243
aliases:
  - GHSA-h9j7-5xvc-qhg5
  - PYSEC-2024-235
  - PYSEC-2026-1509
title: langchain Server-Side Request Forgery vulnerability
summary: langchain Server-Side Request Forgery vulnerability
severity: low
cvss: 3.7
cvssVector: 'CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:N'
vendor: langchain
product: langchain
ecosystem: pip
affected:
  - langchain < 0.1.0
patched:
  - langchain 0.1.0
published: '2024-02-26'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-h9j7-5xvc-qhg5'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-0243'
  - url: 'https://github.com/langchain-ai/langchain/pull/15559'
  - url: >-
      https://github.com/langchain-ai/langchain/commit/bf0b3cc0b5ade1fb95a5b1b6fa260e99064c2e22
  - url: 'https://github.com/langchain-ai/langchain'
  - url: >-
      https://github.com/langchain-ai/langchain/blob/bf0b3cc0b5ade1fb95a5b1b6fa260e99064c2e22/libs/community/langchain_community/document_loaders/recursive_url_loader.py#L51-L51
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/langchain-exa/PYSEC-2024-235.yaml
  - url: 'https://huntr.com/bounties/370904e7-10ac-40a4-a8d4-e2d16e1ca861'
tags:
  - osv
  - pip
epss: 0.00517
epssPercentile: 0.42975
ingestedAt: '2026-07-08T18:25:50.033Z'
---

## Overview

With the following crawler configuration:

```python
from bs4 import BeautifulSoup as Soup

url = "https://example.com"
loader = RecursiveUrlLoader(
    url=url, max_depth=2, extractor=lambda x: Soup(x, "html.parser").text 
)
docs = loader.load()
```

An attacker in control of the contents of `https://example.com` could place a malicious HTML file in there with links like "https://example.completely.different/my_file.html" and the crawler would proceed to download that file as well even though `prevent_outside=True`.

https://github.com/langchain-ai/langchain/blob/bf0b3cc0b5ade1fb95a5b1b6fa260e99064c2e22/libs/community/langchain_community/document_loaders/recursive_url_loader.py#L51-L51

Resolved in https://github.com/langchain-ai/langchain/pull/15559

## Affected packages

- `langchain < 0.1.0`

## Remediation

Upgrade to a patched release:

- `langchain 0.1.0`
