CVE-2023-32786

    Dashboard / Vulnerabilities / CVE-2023-32786

    CVE-2023-32786

    Published: 20 Oct 2023Last Modified: 12 Aug 2026

    Summary:

    Details: In Langchain through 0.0.155, prompt injection allows an attacker to force the service to retrieve data from an arbitrary URL, essentially providing SSRF and potentially injecting content into downstream tasks.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 0
    Fixed -None

    Affected versions

    v0.0.155
    v0.0.154
    v0.0.153
    v0.0.152
    v0.0.151
    v0.0.150
    v0.0.149
    v0.0.147
    v0.0.146
    v0.0.145
    v0.0.144
    v0.0.143
    v0.0.142
    v0.0.141
    v0.0.140
    v0.0.139
    v0.0.138
    v0.0.137
    v0.0.136
    v0.0.135
    v0.0.134
    v0.0.133
    v0.0.132
    v0.0.131
    v0.0.130
    v0.0.129
    v0.0.128
    v0.0.127
    v0.0.126
    v0.0.125
    v0.0.124
    v0.0.123
    v0.0.122
    v0.0.121
    v0.0.120
    v0.0.119
    v0.0.118
    v0.0.117
    v0.0.116
    v0.0.115
    v0.0.114
    v0.0.113
    v0.0.112
    v0.0.111
    v0.0.110
    v0.0.109
    v0.0.108
    v0.0.107
    v0.0.106
    v0.0.105
    v0.0.104
    v0.0.103
    v0.0.102
    v0.0.101
    v0.0.100
    v0.0.99
    v0.0.98
    v0.0.97
    v0.0.96
    v0.0.95
    v0.0.94
    v0.0.93
    v0.0.92
    v0.0.91
    v0.0.90
    v0.0.89
    v0.0.88
    v0.0.87
    v0.0.86
    v0.0.85
    v0.0.84
    v0.0.83
    v0.0.82
    v0.0.81
    v0.0.80
    v0.0.79
    v0.0.78
    v0.0.77
    v0.0.76
    v0.0.75
    v0.0.74
    v0.0.73
    v0.0.72
    v0.0.71
    v0.0.70
    v0.0.69
    v0.0.68
    v0.0.67
    v0.0.66
    v0.0.65
    v0.0.64

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2023-32786 | CVE-DB