CVE-2023-32786General(langchain / langchain)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In Langchain through 0.0.155, prompt injection allows an attacker to force the service to retrieve data from an arbitrary URL, essentially providing SSRF and potentially injecting content into downstream tasks.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • langchain

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-04-30); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
langchain

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-30: 1Mentions · 2026-05-27: 1Technical Details · 2026-04-30: 1Technical Details · 2026-05-27: 104-3005-27
Signal classification1 categories
General
2100.0%
Full discourse2 posts
  • The Signal@thesignalnow
    General

    Connect it to a file system, a shell, or an API, and the threat model inverts. A prompt injection becomes a control-flow hijack. Think of CVE-2023-32786, where a malicious doc in a LangChain agent could execute arbitrary code through its file-reading tool.

    Post summary

    The text references CVE‑2023‑32786, noting that a malicious document in a LangChain agent’s file‑reading tool can lead to arbitrary code execution, but does not mention a PoC, exploit code, active exploitation, or a patch.

    1000066
    541 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVE-2023-29374 (LangChain's llmmath chain) and CVE-2023-32786 (LangChain APIChain) both exploit this pattern — injecting adversarial text through tool outputs that the LLM then faithfully executes. The persistence is session-scoped, but the damage can include credential…

    Post summary

    The excerpt describes two CVEs in LangChain that allow adversarial text injection through tool outputs, leading to LLM execution with session‑scoped persistence and potential credential compromise.

    1000071
    128 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applangchainlangchain---

Explore more