Server-Side Request Forgery Vulnerability in Langchain Community by Langchain AI
CVE-2025-2828

8.4HIGH

Key Information:

Vendor
CVE Published:
23 June 2025

What is CVE-2025-2828?

A Server-Side Request Forgery (SSRF) vulnerability exists in the RequestsToolkit component of the langchain-community package. This vulnerability arises from insufficient restrictions on requests to external internet addresses, inadvertently allowing access to local addresses. An attacker could exploit this flaw to conduct port scanning, gain access to local services, obtain instance metadata from cloud providers like Azure and AWS, and interact with servers on the internal network. The issue has been addressed in version 0.0.28 of the langchain-community package.

Affected Version(s)

langchain-ai/langchain < 0.0.28

References

CVSS V3.0

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-2828 : Server-Side Request Forgery Vulnerability in Langchain Community by Langchain AI