In Langchain before 0.0.247, prompt injection allows execution of arbitrary code against the SQL service provided by the chain.
"https://github.com/pypa/advisory-database/blob/main/vulns/langchain/PYSEC-2026-372.yaml"