VDB
Sign up
HIGH7.5

PYSEC-2026-1508

Langchain Server-Side Request Forgery vulnerability

Quick fix

PYSEC-2026-1508 — langchain: upgrade to the fixed version with the command below.

pip install --upgrade 'langchain>=0.0.329'

Details

In Langchain before 0.0.329, prompt injection allows an attacker to force the service to retrieve data from an arbitrary URL, essentially providing SSRF and potentially injecting content into downstream tasks.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/langchain
Introduced in: 0Fixed in: 0.0.329
Fixpip install --upgrade 'langchain>=0.0.329'

References