{"data":{"id":"7c404b6c-f1d6-4f96-a44e-51441c3403e1","title":"GHSA-h9j7-5xvc-qhg5: langchain Server-Side Request Forgery vulnerability","summary":"The langchain RecursiveUrlLoader in libs/community, in langchain_community/document_loaders/recursive_url_loader.py, can be made to fetch URLs outside the start site. An attacker who controls the content at the crawled URL can add links to other hosts, such as https://example.completely.different/my_file.html, and the crawler downloads them even when prevent_outside=True is set.","solution":"Resolved in https://github.com/langchain-ai/langchain/pull/15559","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-h9j7-5xvc-qhg5","publishedAt":"2024-02-26T18:30:29.000Z","cveId":"CVE-2024-0243","cweIds":["CWE-918"],"cvssScore":"3.7","cvssSeverity":"low","severity":"low","attackType":["other"],"issueType":"vulnerability","affectedPackages":["langchain@< 0.1.0 (fixed: 0.1.0)"],"affectedPackageNames":["langchain"],"affectedPackageRefs":["pypi:langchain"],"affectedVendors":["LangChain"],"affectedVendorsRaw":["LangChain","langchain_community RecursiveUrlLoader"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":"CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:N","attackVector":"local","attackComplexity":"high","privilegesRequired":"high","userInteraction":"required","exploitMaturity":"unknown","epssScore":0.00517,"epssCheckedAt":"2026-10-10T04:57:06.161Z","kevDateAdded":null,"advisoryAliases":["GHSA-h9j7-5xvc-qhg5"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2024-02-26T18:30:29.000Z","capecIds":["CAPEC-664"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity"],"aiComponentTargeted":"rag","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null}}