In Langchain through 0.0.155, prompt injection allows an attacker to force the service to retrieve data from an arbitrary URL, essentially providing SSRF and potentially injecting content into downstream tasks.
{ "versions": [ { "introduced": "0" }, { "last_affected": "0.0.155" } ] }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-32786.json"