VYPR
High severityNVD Advisory· Published Oct 20, 2023· Updated Sep 12, 2024

CVE-2023-32786

CVE-2023-32786

Description

In Langchain through 0.0.155, prompt injection allows an attacker to force the service to retrieve data from an arbitrary URL, essentially providing SSRF and potentially injecting content into downstream tasks.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

In Langchain <=0.0.155, prompt injection enables SSRF by forcing arbitrary URL retrieval, potentially injecting malicious content into downstream tasks.

The vulnerability lies in Langchain's APIChain module, which constructs URLs based on user prompts. An attacker can inject a new base URL into the prompt, causing the application to fetch data from an arbitrary URL instead of the intended API. This is a server-side request forgery (SSRF) flaw, as the application makes requests on behalf of the server. [1][4]

Exploitation requires no special privileges beyond the ability to provide a prompt to a Langchain-powered service. The attacker crafts a malicious prompt that overrides the intended API endpoint, as demonstrated in reference [4] where the base URL is changed to https://api.ipify.org?format=json to retrieve the server's external IP address. The service then fetches and processes the response from the attacker-controlled URL. [4]

Successful exploitation allows an attacker to make requests to internal or external URLs, potentially accessing sensitive internal resources (SSRF) or injecting attacker-controlled content into the LLM's downstream tasks. This could lead to data exfiltration, poisoning of subsequent LLM responses, or bypassing access controls. [1]

The vulnerability affects Langchain through version 0.0.155. Later versions, including release v0.0.329, have implemented fixes. Users are strongly advised to upgrade to a patched version to mitigate the risk. [2][3]

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
langchainPyPI
< 0.0.3290.0.329

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.