{"data":{"id":"3168406e-a5c6-497d-a4e8-ee5ead4afa3a","title":"GHSA-8h5w-f6q9-wg35: Langchain SQL Injection vulnerability","summary":"LangChain versions before 0.0.247 are affected by a flaw in the SQL chain. Prompt injection allows an attacker to execute arbitrary code against the SQL service that the chain provides.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-8h5w-f6q9-wg35","publishedAt":"2023-10-21T00:30:47.000Z","cveId":"CVE-2023-32785","cweIds":["CWE-74","CWE-89"],"cvssScore":"9.8","cvssSeverity":"critical","severity":"critical","attackType":["prompt_injection"],"issueType":"vulnerability","affectedPackages":["langchain@< 0.0.247 (fixed: 0.0.247)"],"affectedPackageNames":["langchain"],"affectedPackageRefs":["pypi:langchain"],"affectedVendors":["LangChain"],"affectedVendorsRaw":["LangChain"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"epssCheckedAt":"2026-10-10T04:57:05.562Z","kevDateAdded":null,"advisoryAliases":["GHSA-8h5w-f6q9-wg35"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2023-10-21T00:30:47.000Z","capecIds":["CAPEC-66"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"rag","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null}}