CVE-2025-2828
LangChain Community SSRF vulnerability exists in RequestsToolkit component
描述
A Server-Side Request Forgery (SSRF) vulnerability exists in the RequestsToolkit component of the langchain-community package (specifically, langchain_community.agent_toolkits.openapi.toolkit.RequestsToolkit) in langchain-ai/langchain version 0.0.27. This vulnerability occurs because the toolkit does not enforce restrictions on requests to remote internet addresses, allowing it to also access local addresses. As a result, an attacker could exploit this flaw to perform port scans, access local services, retrieve instance metadata from cloud environments (e.g., Azure, AWS), and interact with servers on the local network. This issue has been fixed in version 0.0.28.
如何修補 CVE-2025-2828
要修補 CVE-2025-2828,請將受影響套件升級到下列已修補版本。
- —升級至 0.0.28 或更新版本
- —升級至 e188d4ecb085d4561a0be3c583d26aa9c2c3283f 或更新版本
CVE-2025-2828 正在被利用嗎?
中等 — EPSS 為 14.1%,可持續追蹤但非最高優先。
受影響套件(2)
- from 0, < 0.0.28
- from 0, < e188d4ecb085d4561a0be3c583d26aa9c2c3283f | from 0, < 0.0.28
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.4 | CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H |