CVE-2025-6984
HIGH7.5EPSS 1.9%Langchain Community Vulnerable to XML External Entity (XXE) Attacks
發布日:2025/9/4修改日:2026/2/4
描述
The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The vulnerability arises from the use of etree.iterparse() without disabling external entity references, which can lead to sensitive information disclosure. An attacker could exploit this by crafting a malicious XML payload that references local files, potentially exposing sensitive data such as /etc/passwd. This issue has been fixed in 0.3.27 of langchain-community.
受影響套件(1)
- PyPI/langchain-communityfrom 0, < 0.3.27
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
參考連結(5)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2025-6984
- PATCHhttps://github.com/langchain-ai/langchain-community
- WEBhttps://github.com/langchain-ai/langchain/blob/d79b5813a0b3b243c612b77013768995e46c4337/libs/langchain/langchain/document_loaders/evernote.py#L1-L23
- WEBhttps://github.com/langchain-ai/langchain-community/commit/e842452108089524e22c3a2ced851c021884556f
- WEBhttps://huntr.com/bounties/a6b521cf-258c-41c0-9edb-d8ef976abb2a