CVE-2026-72848: SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documented restrict_to_same_d
Summary
A security flaw in LangChain's SitemapLoader allows attackers to bypass the restrict_to_same_domain control (a setting meant to prevent the tool from fetching content from other websites). The bug happens because nested sitemaps are fetched without checking the domain restriction, so an attacker controlling a sitemap can point it to internal addresses and leak the content back to the caller.
Vulnerability Details
8.6(high)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
network
low
none
none
August 20, 2026
Classification
Taxonomy References
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-72848
First tracked: August 20, 2026 at 08:08 PM
Classified by LLM (prompt v3) · confidence: 95%