—
PYSEC-2023-205
Details
LangChain before 0.0.317 allows SSRF via document_loaders/recursive_url_loader.py because crawling can proceed from an external server to an internal server.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI / langchain
Introduced in:
0 Fixed in: 9ecb7240a480720ec9d739b3877a52f76098a2b8 Fix
pip install --upgrade 'langchain>=9ecb7240a480720ec9d739b3877a52f76098a2b8'