Bug 2322452 (CVE-2024-8309) - CVE-2024-8309 langchain: SQL Injection in langchain-ai/langchain
Summary: CVE-2024-8309 langchain: SQL Injection in langchain-ai/langchain
Keywords:
Status: NEW
Alias: CVE-2024-8309
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2024-10-29 14:01 UTC by OSIDB Bzimport
Modified: 2025-06-17 08:27 UTC (History)
31 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2024-10-29 14:01:59 UTC
A vulnerability in the GraphCypherQAChain class of langchain-ai/langchain version 0.2.5 allows for SQL injection through prompt injection. This vulnerability can lead to unauthorized data manipulation, data exfiltration, denial of service (DoS) by deleting all data, breaches in multi-tenant security environments, and data integrity issues. Attackers can create, update, or delete nodes and relationships without proper authorization, extract sensitive data, disrupt services, access data across different tenants, and compromise the integrity of the database.


Note You need to log in before you can comment on or make changes to this bug.