logo

Vulnerabilities in LangChain Gen AI

ID: 2e73bf3d-e83c-59a3-ba93-a1eec8182d6d

STIX ID: report--2e73bf3d-e83c-59a3-ba93-a1eec8182d6d

Feed Name: Palo Alto Networks Unit 42

Threat Score
70/100

Date Published: 2024-07-23

Date Updated: 2026-04-28

Author: Yiheng An, Haozhe Zhang and Qi Deng

...
...

Palo Alto Networks researchers discovered and analyzed two vulnerabilities in the LangChain ecosystem: CVE-2023-46229, an SSRF in the SitemapLoader that can fetch intranet resources and leak sensitive data, and CVE-2023-44467, a prompt-injection flaw in LangChain Experimental's PALChain that can result in remote code execution; both issues were reported to LangChain, mitigations and patches were released, and guidance for reducing risk is provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.