A vulnerability was found in LangChain langchain_community 0.0.26. It has been classified as critical. Affected is the function load_local in the library libs/community/langchain_community/retrievers/tfidf.py of the component TFIDFRetriever. The manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 0.0.27 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-255372.
References
Link | Resource |
---|---|
https://github.com/bayuncao/vul-cve-16 | Broken Link |
https://github.com/bayuncao/vul-cve-16 | Broken Link |
https://github.com/bayuncao/vul-cve-16/tree/main/PoC.pkl | Broken Link |
https://github.com/bayuncao/vul-cve-16/tree/main/PoC.pkl | Broken Link |
https://github.com/langchain-ai/langchain/pull/18695 | Patch |
https://github.com/langchain-ai/langchain/pull/18695 | Patch |
https://vuldb.com/?ctiid.255372 | Permissions Required |
https://vuldb.com/?ctiid.255372 | Permissions Required |
https://vuldb.com/?id.255372 | Permissions Required |
https://vuldb.com/?id.255372 | Permissions Required |
Configurations
History
04 Mar 2025, 12:25
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
CWE | ||
References | () https://github.com/langchain-ai/langchain/pull/18695 - Patch | |
References | () https://github.com/bayuncao/vul-cve-16 - Broken Link | |
References | () https://vuldb.com/?ctiid.255372 - Permissions Required | |
References | () https://vuldb.com/?id.255372 - Permissions Required | |
References | () https://github.com/bayuncao/vul-cve-16/tree/main/PoC.pkl - Broken Link | |
First Time |
Langchain langchain
Langchain |
|
CPE | cpe:2.3:a:langchain:langchain:0.0.26:*:*:*:community:*:*:* |
13 Mar 2024, 16:15
Type | Values Removed | Values Added |
---|---|---|
Summary | A vulnerability was found in LangChain langchain_community 0.0.26. It has been classified as critical. Affected is the function load_local in the library libs/community/langchain_community/retrievers/tfidf.py of the component TFIDFRetriever. The manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 0.0.27 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-255372. |
10 Mar 2024, 02:16
Type | Values Removed | Values Added |
---|---|---|
References |
|
01 Mar 2024, 12:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-03-01 12:15
Updated : 2025-03-04 12:25
NVD link : CVE-2024-2057
Mitre link : CVE-2024-2057
JSON object : View
Products Affected
langchain
- langchain
CWE
No CWE.