Vulnerability record · CVE-2023-46229 · published 19 October 2023
CVE-2023-46229: LangChain RecursiveUrlLoader SSRF via external-to-internal crawl
Langchain · Langchain
LangChain before 0.0.317 allows server-side request forgery in document_loaders/recursive_url_loader.py because crawling can proceed from an external server to an internal server. An attacker who controls or influences a crawled URL can make the application issue requests to internal network resources. This matters because LangChain is widely embedded in LLM applications that fetch and process web content.
Description
LangChain before 0.0.317 allows SSRF via document_loaders/recursive_url_loader.py because crawling can proceed from an external server to an internal server.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with no privileges required and a very high EPSS percentile, though exploitation is not confirmed in KEV and user interaction is needed.
What it is
LangChain before 0.0.317 allows server-side request forgery in document_loaders/recursive_url_loader.py because crawling can proceed from an external server to an internal server. An attacker who controls or influences a crawled URL can make the application issue requests to internal network resources. This matters because LangChain is widely embedded in LLM applications that fetch and process web content.
Impact
An attacker can cause the LangChain host to make requests to internal services, potentially reaching internal-only endpoints and returning their content into the application's document pipeline. The CVSS vector rates high confidentiality, integrity and availability impact, though the record does not detail specific downstream effects.
Attack surface
Reached over the network through the recursive URL loader when it processes an attacker-supplied or attacker-influenced URL. The CVSS vector requires user interaction (UI:R) and no privileges (PR:N), so a victim must trigger the crawl on the crafted input.
Exploitation
Not listed in CISA KEV and no public exploit references are tagged in the record. EPSS is high at roughly 0.447 probability (98.7th percentile), indicating elevated likelihood of exploitation activity, but the record does not confirm in-the-wild use.
What to do
- Upgrade LangChain to 0.0.317 or later, applying the patch commit 9ecb7240a480720ec9d739b3877a52f76098a2b8.
- Restrict outbound network access from LangChain hosts so crawls cannot reach internal RFC1918 or link-local ranges.
- Validate and allowlist URLs passed to RecursiveUrlLoader before crawling, rejecting internal hostnames and IPs.
- Run document loaders in a sandboxed network segment with egress filtering and no access to internal services.
Detection
- Monitor outbound HTTP requests from LangChain hosts to internal IP ranges or unexpected internal hostnames.
- Alert on RecursiveUrlLoader or recursive_url_loader usage with URLs resolving to private address space.
- Review application logs for crawl targets that redirect from external to internal hosts.
- Watch for unusual DNS resolutions or connection attempts to metadata endpoints such as 169.254.169.254.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-46229 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-46229), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.