PYSEC-2024-115

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/langchain-community/PYSEC-2024-115.yaml
JSON Data
https://api.test.osv.dev/v1/vulns/PYSEC-2024-115
Aliases
Published
2024-11-05T16:04:14Z
Modified
2026-07-09T16:45:07Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A vulnerability in the GraphCypherQAChain class of langchain-ai/langchain-community version 0.2.5 allows for SQL injection through prompt injection. This vulnerability can lead to unauthorized data manipulation, data exfiltration, denial of service (DoS) by deleting all data, breaches in multi-tenant security environments, and data integrity issues. Attackers can create, update, or delete nodes and relationships without proper authorization, extract sensitive data, disrupt services, access data across different tenants, and compromise the integrity of the database.

References

Affected packages

PyPI / langchain-community

Package

Name
langchain-community
View open source insights on deps.dev
Purl
pkg:pypi/langchain-community

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0.2.0
Fixed
0.3.0

Affected versions

0.*
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.9
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.3.0.dev1
0.3.0.dev2

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/langchain-community/PYSEC-2024-115.yaml"