Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

[GHSA-q25c-c977-4cmh] Server-Side Request Forgery in langchain #4630

Conversation

eyurtsev
Copy link

Updates

  • Affected products
  • Description
  • References
  • Summary

Comments
Patch has been released:

langchain-ai/langchain#24451
https://github.com/langchain-ai/langchain/releases/tag/langchain-community%3D%3D0.2.9

The original CVE was not associated with the correct package. Huntr does not support mono-repos at the moment, so many issues get classified as corresponding to langchain package, even though the code corresponds to the langchain-community package. The report iself was also unclear and did not differentiate between the repository vs. the package.

@github-actions github-actions bot changed the base branch from main to eyurtsev/advisory-improvement-4630 July 24, 2024 14:42
@advisory-database advisory-database bot merged commit bf54aa7 into eyurtsev/advisory-improvement-4630 Jul 24, 2024
2 checks passed
@advisory-database
Copy link
Contributor

Hi @eyurtsev! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

@advisory-database advisory-database bot deleted the eyurtsev-GHSA-q25c-c977-4cmh branch July 24, 2024 17:34
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant