Database/AI/ML frameworks & serving
LangChain (Web Research Retriever): SSRF
CVSS 7.7CVE-2024-3095AI/ML frameworks & servingcurated
Impact
SSRF
Who can reach it
Attacker-supplied URL or retrieved content
What to do
Upgrade; block internal egress
References
Related entries
- LangGraph MongoDB checkpoint and store: filter dicts allow MQL operator injection across tenantsCVE-2026-55253 · langgraph-checkpoint-mongodb / langgraph-store-mongodb (MongoDBSaver.list, MongoDBStore.search filters)High
- Kedro-Datasets PyTorchDataset: torch.load without weights_only executes code from .pt filesCVE-2026-62997 · kedro-datasets PyTorchDataset (kedro_datasets_experimental.pytorch)High
- SitemapLoader: nested sitemap entries skip restrict_to_same_domain, giving readable SSRFCVE-2026-72848 · langchain-community SitemapLoader (nested sitemap index entries)High
- JupyterLab: missing await skips extension allowlist check for direct PyPIExtensionManager callersCVE-2026-73626 · JupyterLab PyPIExtensionManager.install() (extension allowlist/blocklist enforcement)High
- Headroom LLM proxy: client-chosen upstream base URL enables SSRF and leaks the Authorization headerCVE-2026-77775 · Headroom LLM proxy (x-headroom-base-url upstream selection)High
- JupyterLab: XSS via untrusted notebook contentCVE-2024-43805 · JupyterLabHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.