Server-side Request Forgery In Recursive URL Loader
Published Feb 24, 2024
8.1
HIGHCVSS 3.1
EPSS 0.52%
Description
With the following crawler configuration:
```python from bs4 import BeautifulSoup as Soup
url = "https://example.com" loader = RecursiveUrlLoader( url=url, max_depth=2, extractor=lambda x: Soup(x, "html.parser").text ) docs = loader.load() ```
An attacker in control of the contents of `https://example.com` could place a malicious HTML file in there with links like "https://example.completely.different/my_file.html" and the crawler would proceed to download that file as well even though `prevent_outside=True`.
Resolved in https://github.com/langchain-ai/langchain/pull/15559
Affected products
-
- Version unspecifiedStatusaffectedConstraints<0.1.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Langchain-AI | Langchain-Ai/langchain | n/a |
|
-
- Version 0StatusaffectedConstraints<0.1.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Langchain-AI | Langchain-Ai\/langchain | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (7)
- https://github.com/advisories/GHSA-h9j7-5xvc-qhg5 Advisory
- https://github.com/langchain-ai/langchain/blob/bf0b3cc0b5ade1fb95a5b1b6fa260e99064c2e22/libs/community/langchain_community/document_loaders/recursive_url_loader.py#L51-L51
- https://github.com/langchain-ai/langchain/commit/bf0b3cc0b5ade1fb95a5b1b6fa260e99064c2e22 Patch
- https://github.com/langchain-ai/langchain/pull/15559 Issue TrackingPatch
- https://github.com/pypa/advisory-database/tree/main/vulns/langchain-exa/PYSEC-2024-235.yaml
- https://huntr.com/bounties/370904e7-10ac-40a4-a8d4-e2d16e1ca861 ExploitIssue TrackingThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-0243
Change history (0)
No recorded changes yet.