Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
CVE-2025-9556
Vulnerability Description
Langchaingo supports the use of jinja2 syntax when parsing prompts, which is in turn parsed using the gonja library v1.5.3. Gonja supports include and extends syntax to read files, which leads to a server side template injection vulnerability within langchaingo, allowing an attacker to insert a statement into a prompt to read the "etc/passwd" file.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
LangChain Go 安全漏洞
Vulnerability Description
LangChain Go是Travis Cline个人开发者的一个用Go编写基于LLM的程序的简单框架。 LangChain Go 0.1.14版本存在安全漏洞,该漏洞源于支持include和extends语法读取文件,可能导致服务器端模板注入攻击。
CVSS Information
N/A
Vulnerability Type
N/A