In Langchain before 0.0.247, prompt injection allows execution of arbitrary code against the SQL service provided by the chain.
{
"severity": "CRITICAL",
"github_reviewed_at": "2023-10-24T01:41:25Z",
"cwe_ids": [
"CWE-74",
"CWE-89"
],
"nvd_published_at": "2023-10-20T22:15:10Z",
"github_reviewed": true
}