CVE-2025-6984
Langchain Community Vulnerable to XML External Entity (XXE) Attacks
7.5
HIGH
CVSS 3.1
EPSS 1.5%
描述
The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The vulnerability arises from the use of etree.iterparse() without disabling external entity references, which can lead to sensitive information disclosure. An attacker could exploit this by crafting a malicious XML payload that references local files, potentially exposing sensitive data such as /etc/passwd. This issue has been fixed in 0.3.27 of langchain-community.
如何修補 CVE-2025-6984
要修補 CVE-2025-6984,請將受影響套件升級到下列已修補版本。
- —升級至 0.3.27 或更新版本
- —升級至 0.3.27 或更新版本
CVE-2025-6984 正在被利用嗎?
低 — EPSS 為 1.5%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 0.3.27
- from 0, < 0.3.27
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |