漏洞与安全社区 / 第三方国际
CVE-2024-8309: Langchain SQL Injection vulnerability
今日摘要使用自己的 API,仅供个人查看
来源摘要
A vulnerability in the GraphCypherQAChain class of langchain-ai/langchain version 0.2.5 allows for SQL injection through prompt injection. This vulnerability can lead to unauthorized data manipulation, data exfiltration, denial of service (DoS) by deleting all data, breaches in multi-tenant security environments, and data integrity issues. Attackers can create, update, or delete nodes and relationships without proper authorization, extract sensitive data, disrupt services, access data across different tenants, and compromise the integrity of the database.
阅读原始来源- 来源
- LangChain 安全公告 · 社区 / 第三方
- 来源发布
- 2024/10/29 23:32
- 来源更新
- 2024/11/13 03:58
- 首次采集
- 2026/09/19 13:00
本文为公开信息索引与摘要,详情及后续变化请以原始来源为准。