Skip to content
LowVulnerability

GHSA-h9j7-5xvc-qhg5: langchain Server-Side Request Forgery vulnerability

Published
Record updated
View JSON
Affected
  • langchain < 0.1.0
Fixed in
0.1.0
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.5%

Summary

The langchain RecursiveUrlLoader in libs/community, in langchain_community/document_loaders/recursive_url_loader.py, can be made to fetch URLs outside the start site. An attacker who controls the content at the crawled URL can add links to other hosts, such as https://example.completely.different/my_file.html, and the crawler downloads them even when prevent_outside=True is set.

Mitigation

Resolved in https://github.com/langchain-ai/langchain/pull/15559