Vulnerabilities in LangChain Gen AI
ID: 2e73bf3d-e83c-59a3-ba93-a1eec8182d6d
STIX ID: report--2e73bf3d-e83c-59a3-ba93-a1eec8182d6d
Feed Name: Palo Alto Networks Unit 42
Threat Score
Palo Alto Networks researchers discovered and analyzed two vulnerabilities in the LangChain ecosystem: CVE-2023-46229, an SSRF in the SitemapLoader that can fetch intranet resources and leak sensitive data, and CVE-2023-44467, a prompt-injection flaw in LangChain Experimental's PALChain that can result in remote code execution; both issues were reported to LangChain, mitigations and patches were released, and guidance for reducing risk is provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
