Beveiligingsadvies

CVE-2025-46059

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-07-29 00:00:00
Laatst bijgewerkt 2025-08-03 23:20:43
Toegewezen door mitre
CVSS-score 9.8
Status PUBLISHED

Beschrijving

langchain-ai v0.3.51 was discovered to contain an indirect prompt injection vulnerability in the GmailToolkit component. This vulnerability allows attackers to execute arbitrary code and compromise the application via a crafted email message. NOTE: this is disputed by the Supplier because the code-execution issue was introduced by user-written code that does not adhere to the LangChain security practices.