Description
A vulnerability in the GraphCypherQAChain class of langchain-ai/langchainjs versions 0.2.5 and all versions with this class allows for prompt injection, leading to SQL injection.
Recommendation
Update the @langchain/community package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.3.3
- Patched version(s): 0.3.3
References
Related Issues
- LangChain Community: redirect chaining can lead to SSRF bypass via RecursiveUrlLoader - CVE-2026-27795
- @langchain/community affected by SSRF Bypass in RecursiveUrlLoader via insufficient URL origin validation - CVE-2026-26019
- Langchain Path Traversal vulnerability - CVE-2024-7774
- squirrelly Code Injection vulnerability - CVE-2024-40453
You might also like:
- Tags:
- npm
- @langchain/community
Anything's wrong? Let us know Last updated on November 01, 2024


