LangChain 是一个用于构建大语言模型(LLM)驱动应用的框架。在 1.3.1 版本之前,MongoDBChatMessageHistory 组件在运行时未对不可信的、结构化的会话标识符强制执行文档中声明的字符串类型。这导致当多个用户的历史记录存储在同一 MongoDB 集合中时,该标识符可能被解释为 MongoDB 查询条件,而非字面量值。因此,攻击者若能调用聊天历史操作,即可读取、修改或删除其他用户存储的对话数据。对于使用经过身份验证、由服务器控制的字符串标识符的应用程序,则不受此漏洞影响。该问题已在 1
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| @langchain | mongodb | < 1.3.1 |
affected |
| langchain-ai | langchainjs | < 1.5.14 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| langchain-ai | langchainjs | < 1.5.14 | - |
|
| @langchain | mongodb | < 1.3.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet