SQL Injection Affecting langchain package, versions [,0.0.276)
Threat Intelligence
Exploit Maturity
Proof of concept
EPSS
0.13% (49th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-LANGCHAIN-6026731
- published 23 Oct 2023
- disclosed 20 Oct 2023
- credit Rich Harang
Introduced: 20 Oct 2023
CVE-2023-32785 Open this link in a new tabHow to fix?
Upgrade langchain
to version 0.0.276 or higher.
Overview
langchain is a Building applications with LLMs through composability
Affected versions of this package are vulnerable to SQL Injection through the service provided by the chain. An attacker can execute arbitrary SQL by injecting it into a db_chain()
prompt.
References
CVSS Scores
version 3.1