CVE-2024-0243: langchain Server-Side Request Forgery vulnerability
来源摘要
With the following crawler configuration: ```python from bs4 import BeautifulSoup as Soup url = "https://example.com" loader = RecursiveUrlLoader( url=url, max_depth=2, extractor=lambda x: Soup(x, "html.parser").text ) docs = loader.load() ``` An attacker in control of the contents of `https://example.com` could place a malicious HTML file in there with links like "https://example.completely.different/my_file.html" and the crawler would proceed to download that file as well even though `prevent_outside=True`. https://github.com/langchain-ai/langchain/blob/bf0b3cc0b5ade1fb95a5b1b6fa260e99064c2e22/libs/community/langchain_community/document_loaders/recursive_url_loader.py#L51-L51 Resolved in https://github.com/langchain-ai/langchain/pull/15559
阅读原始来源- 来源
- LangChain 安全公告 · 社区 / 第三方
- 来源发布
- 2024/02/27 02:30
- 来源更新
- 2026/03/17 13:03
- 首次采集
- 2026/09/19 13:00
本文为公开信息索引与摘要,详情及后续变化请以原始来源为准。