- Description
- A Server-Side Request Forgery (SSRF) vulnerability exists in the RequestsToolkit component of the langchain-community package (specifically, langchain_community.agent_toolkits.openapi.toolkit.RequestsToolkit) in langchain-ai/langchain version 0.0.27. This vulnerability occurs because the toolkit does not enforce restrictions on requests to remote internet addresses, allowing it to also access local addresses. As a result, an attacker could exploit this flaw to perform port scans, access local services, retrieve instance metadata from cloud environments (e.g., Azure, AWS), and interact with servers on the local network. This issue has been fixed in version 0.0.28.
- Source
- security@huntr.dev
- NVD status
- Analyzed
CVSS 3.1
- Type
- Primary
- Base score
- 10
- Impact score
- 6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
CVSS 3.0
- Type
- Secondary
- Base score
- 8.4
- Impact score
- 6
- Exploitability score
- 1.7
- Vector string
- CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
- Severity
- HIGH
- security@huntr.dev
- CWE-918
- Hype score
- Not currently trending
[CVE-2025-2828: HIGH] Vulnerability alert: SSRF flaw in langchain-ai/langchain v0.0.27's RequestsToolkit component allows attackers unauthorized access to local addresses. Update to v0.0.28 for protection.#cve,CVE-2025-2828,#cybersecurity https://t.co/oDwaX92vsQ https://t.co/XIot
@CveFindCom
23 Jun 2025
62 Impressions
0 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes
CVE-2025-2828 A Server-Side Request Forgery (SSRF) vulnerability exists in the RequestsToolkit component of the langchain-community package (specifically, langchain_community.agent_t… https://t.co/7t2IrqmZiA
@CVEnew
23 Jun 2025
454 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:langchain:langchain:*:*:*:*:community:*:*:*",
"vulnerable": true,
"matchCriteriaId": "70F7E7BB-6417-4B87-997A-F2028B53849F",
"versionEndExcluding": "0.0.28"
}
],
"operator": "OR"
}
]
}
]