Eugene Yurtsev
17 exploits
Active since Oct 2023
langchain-ai/langchain <0.2.5 - SQL Injection
CVSS 9.8
langchain-core 1.0.0-1.0.6 - Template Injection via Untrusted Template Strings
LangChain has incomplete f-string validation in prompt templates
CVSS 5.3
LangChain has incomplete f-string validation in prompt templates
CVSS 5.3
LangChain <0.0.306 - Command Injection
CVSS 9.8
langchain < 0.0.317 - Server-Side Request Forgery via Recursive URL Loader
CVSS 8.8
langchain < 0.1.0 - Server-Side Request Forgery via RecursiveUrlLoader
CVSS 8.1
langchain 0.1.4-0.1.34 - Denial of Service via XML Entity Expansion
CVSS 5.9
langchain-experimental < 0.1.8 - Remote Code Execution via Unrestricted Python Attribute Access
CVSS 9.8
langchain < 0.2.5 - Denial of Service via SitemapLoader Recursion
CVSS 4.7
langchain-ai/langchain - Path Traversal
CVSS 8.8
langchain_experimental <0.0.61 - RCE
CVSS 7.8
langchain < 0.2.9 and langchain-community < 0.2.4 - Remote Code Execution via FAISS Deserialization
CVSS 7.8
langchain < 0.0.28 - Server-Side Request Forgery via RequestsToolkit
CVSS 10.0
langgraph-checkpoint-sqlite < 2.0.11 - SQL Injection via Improper String Concatenation
CVSS 7.3
langchain-core 1.0.0-1.0.6 - Template Injection via Untrusted Template Strings
langgraph-checkpoint-sqlite < 3.0.1 - SQL Injection via Metadata Filter Key Interpolation
CVSS 7.3