CRITICAL9.8
PYSEC-2026-372
Langchain SQL Injection vulnerability
Quick fix
PYSEC-2026-372 — langchain: upgrade to the fixed version with the command below.
pip install --upgrade 'langchain>=0.0.247'Details
In Langchain before 0.0.247, prompt injection allows execution of arbitrary code against the SQL service provided by the chain.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2023-32785[ADVISORY]
- https://github.com/langchain-ai/langchain/issues/5923#issuecomment-1696053841[WEB]
- https://gist.github.com/rharang/9c58d39db8c01db5b7c888e467c0533f[WEB]
- https://github.com/langchain-ai/langchain[PACKAGE]
- https://pypi.org/project/langchain[PACKAGE]
- https://github.com/advisories/GHSA-8h5w-f6q9-wg35[ADVISORY]