Vulnerabilities/

@langchain/community SQL Injection vulnerability

Severity:
Low

Description

A vulnerability in the GraphCypherQAChain class of langchain-ai/langchainjs versions 0.2.5 and all versions with this class allows for prompt injection, leading to SQL injection.

Recommendation

Update the @langchain/community package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@langchain/community
Anything's wrong? Let us know Last updated on November 01, 2024

This issue is available in SmartScanner Professional

See Pricing