CVE-2023-32786: Langchain
High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.
In Langchain through 0.0.155, prompt injection allows an attacker to force the service to retrieve data from an arbitrary URL, essentially providing SSRF and potentially injecting content into downstream tasks.
Affected products
- Langchain Langchain: up to and including 0.0.155
Published 2023-10-20. Last modified 2026-06-17.