Back to overview

CVE-2025-9556

CRITICAL
9.8
CVSS 3.1
Description
Langchaingo supports the use of jinja2 syntax when parsing prompts, which is in turn parsed using the gonja library v1.5.3. Gonja supports include and extends syntax to read files, which leads to a server side template injection vulnerability within langchaingo, allowing an attacker to insert a statement into a prompt to read the "etc/passwd" file.

Metadata

CVE ID
CVE-2025-9556
State
PUBLISHED
Assigner
certcc
Reserved
2025-08-27 18:10 UTC
Published
2025-09-12 13:45 UTC
Last updated
2025-11-03 18:14 UTC
Vendor / Product
Langchaingo / Langchaingo
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Langchaingo Langchaingo 0.1.14
Weakness (CWE)
CWESourceDescription
cna CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 adp CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Back to overview