In Langchain through 0.0.155, prompt injection allows an attacker to force the service to retrieve data from an arbitrary URL, essentially providing SSRF and potentially injecting content into downstream tasks.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2023-10-20T00:00:00

Updated: 2023-10-20T21:09:41.414194

Reserved: 2023-05-15T00:00:00


Link: CVE-2023-32786

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-10-20T22:15:10.553

Modified: 2023-10-27T21:44:28.833


Link: CVE-2023-32786

JSON object: View

cve-icon Redhat Information

No data.

CWE