CVE-2023-32785
In Langchain before 0.0.247, prompt injection allows execution of arbitrary code against the SQL service provided by the chain.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://nvd.nist.gov/vuln/detail/CVE-2023-32785, https://github.com/langchain-ai/langchain/issues/5923#issuecomment-1696053841, https://gist.github.com/rharang/9c58d39db8c01db5b7c888e467c0533f, https://github.com/langchain-ai/langchain, https://pypi.org/project/langchain, https://github.com/advisories/GHSA-8h5w-f6q9-wg35