-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stemmed from APIChain's inability to restrict URL domains. The GitHub PR #12747 explicitly adds 'limit_to_domains' validation to APIChain, confirming these functions were vulnerable. The provided exploit example demonstrates how prompt injection in APIChain.run() could force arbitrary URL access. The patch modifies these exact components to enforce domain restrictions, directly linking them to the SSRF vulnerability.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| langchain | pip | < 0.0.329 | 0.0.329 |
KEV Misses 88% of Exploited CVEs- Get the report