Home ยป Database

AVID-2026-R1252

Description

Vulnerability CVE-2023-36189

Details

SQL injection vulnerability in langchain before v0.0.247 allows a remote attacker to obtain sensitive information via the SQLDatabaseChain component.

Reason for inclusion in AVID: CVE-2023-36189 describes a SQL injection vulnerability in the LangChain library (pre-0.0.247) that could let a remote attacker obtain sensitive information via the SQLDatabaseChain component. LangChain is an AI tooling/framework used to build AI/ML pipelines, so the issue affects software components used to build, deploy, and run general-purpose AI systems. It is a security vulnerability with potential data exposure, and the report provides explicit CVE, description, and multiple references, supporting evidence for AVID curation.

References

Affected or Relevant Artifacts

  • Developer: n/a
  • Deployer: n/a
  • Artifact Details:
TypeName
Systemn/a

Impact

AVID Taxonomy Categorization

  • Risk domains: Security
  • SEP subcategories: S0100: Software Vulnerability
  • Lifecycle stages: L06: Deployment

Other information

  • Report Type: Advisory
  • Credits:
  • Date Reported: 2023-07-06
  • Version: 0.3.3
  • AVID Entry