← Vulnerability feed

Vulnerability record · CVE-2023-46229 · published 19 October 2023

CVE-2023-46229: LangChain RecursiveUrlLoader SSRF via external-to-internal crawl

Langchain · Langchain

LangChain before 0.0.317 allows server-side request forgery in document_loaders/recursive_url_loader.py because crawling can proceed from an external server to an internal server. An attacker who controls or influences a crawled URL can make the application issue requests to internal network resources. This matters because LangChain is widely embedded in LLM applications that fetch and process web content.

8.8 CVSS 3.1 High EPSS 45% · top 1.3% CWE-918 · Server-side request forgery (SSRF)
8.8CVSS 3.1 base score
45%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

LangChain before 0.0.317 allows SSRF via document_loaders/recursive_url_loader.py because crawling can proceed from an external server to an internal server.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityCVSS 8.8 with no privileges required and a very high EPSS percentile, though exploitation is not confirmed in KEV and user interaction is needed.

What it is

LangChain before 0.0.317 allows server-side request forgery in document_loaders/recursive_url_loader.py because crawling can proceed from an external server to an internal server. An attacker who controls or influences a crawled URL can make the application issue requests to internal network resources. This matters because LangChain is widely embedded in LLM applications that fetch and process web content.

Impact

An attacker can cause the LangChain host to make requests to internal services, potentially reaching internal-only endpoints and returning their content into the application's document pipeline. The CVSS vector rates high confidentiality, integrity and availability impact, though the record does not detail specific downstream effects.

Attack surface

Reached over the network through the recursive URL loader when it processes an attacker-supplied or attacker-influenced URL. The CVSS vector requires user interaction (UI:R) and no privileges (PR:N), so a victim must trigger the crawl on the crafted input.

Exploitation

Not listed in CISA KEV and no public exploit references are tagged in the record. EPSS is high at roughly 0.447 probability (98.7th percentile), indicating elevated likelihood of exploitation activity, but the record does not confirm in-the-wild use.

What to do

  • Upgrade LangChain to 0.0.317 or later, applying the patch commit 9ecb7240a480720ec9d739b3877a52f76098a2b8.
  • Restrict outbound network access from LangChain hosts so crawls cannot reach internal RFC1918 or link-local ranges.
  • Validate and allowlist URLs passed to RecursiveUrlLoader before crawling, rejecting internal hostnames and IPs.
  • Run document loaders in a sandboxed network segment with egress filtering and no access to internal services.

Detection

  • Monitor outbound HTTP requests from LangChain hosts to internal IP ranges or unexpected internal hostnames.
  • Alert on RecursiveUrlLoader or recursive_url_loader usage with URLs resolving to private address space.
  • Review application logs for crawl targets that redirect from external to internal hosts.
  • Watch for unusual DNS resolutions or connection attempts to metadata endpoints such as 169.254.169.254.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-46229 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-2828Langchain server-side request forgery (ssrf) vulnerabilityA Server-Side Request Forgery (SSRF) vulnerability exists in the RequestsToolkit component of the langchain-community package (specifically, langchai…EPSS 21%9.8CVE-2024-8309Langchain sql injection vulnerabilityA vulnerability in the GraphCypherQAChain class of langchain-ai/langchain version 0.2.5 allows for SQL injection through prompt injection. This vulne…EPSS 14%9.8CVE-2024-7042Langchain sql injection vulnerabilityA vulnerability in the GraphCypherQAChain class of langchain-ai/langchainjs versions 0.2.5 and all versions with this class allows for prompt injecti…EPSS 0.31%9.8CVE-2024-2057Langchain server-side request forgery (ssrf) vulnerabilityA vulnerability was found in LangChain langchain_community 0.0.26. It has been classified as critical. Affected is the function load_local in the lib…EPSS 0.58%9.8CVE-2023-39631Langchain code injection vulnerabilityAn issue in LanChain-ai Langchain v.0.0.245 allows a remote attacker to execute arbitrary code via the evaluate function in the numexpr library.EPSS 1.6%9.8CVE-2023-36281Langchain code injection vulnerabilityAn issue in langchain v.0.0.171 allows a remote attacker to execute arbitrary code via a JSON file to load_prompt. This is related to __subclasses__ …EPSS 3.4%9.8CVE-2023-38896Langchain injection vulnerabilityAn issue in Harrison Chase langchain v.0.0.194 and before allows a remote attacker to execute arbitrary code via the from_math_prompt and from_colore…EPSS 1.8%9.8CVE-2023-39659Langchain injection vulnerabilityAn issue in langchain langchain-ai v.0.0.232 and before allows a remote attacker to execute arbitrary code via a crafted script to the PythonAstREPLT…EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2023-46229), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.