Critical severity9.8NVD Advisory· Published Oct 29, 2024· Updated Jun 17, 2026
CVE-2024-8309
CVE-2024-8309
Description
A vulnerability in the GraphCypherQAChain class of langchain-ai/langchain version 0.2.5 allows for SQL injection through prompt injection. This vulnerability can lead to unauthorized data manipulation, data exfiltration, denial of service (DoS) by deleting all data, breaches in multi-tenant security environments, and data integrity issues. Attackers can create, update, or delete nodes and relationships without proper authorization, extract sensitive data, disrupt services, access data across different tenants, and compromise the integrity of the database.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
langchain-communityPyPI | >= 0.2.0, < 0.2.19 | 0.2.19 |
langchainPyPI | < 0.2.0 | 0.2.0 |
Affected products
4cpe:2.3:a:langchain:langchain:0.2.5:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:langchain:langchain:0.2.5:*:*:*:*:*:*:*
- (no CPE)range: unspecified
- ghsa-coords2 versions
< 0.2.0+ 1 more
- (no CPE)range: < 0.2.0
- (no CPE)range: >= 0.2.0, < 0.2.19
Patches
Vulnerability mechanics
References
6- github.com/langchain-ai/langchain/commit/c2a3021bb0c5f54649d380b42a0684ca5778c255nvdPatchWEB
- huntr.com/bounties/8f4ad910-7fdc-4089-8f0a-b5df5f32e7c5nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-45pg-36p6-83v9ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-8309ghsaADVISORY
- github.com/langchain-ai/langchain/commit/64c317eba05fbac0c6a6fc5aa192bc0d7130972eghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/langchain/PYSEC-2024-115.yamlghsaWEB
News mentions
0No linked articles in our index yet.