VDB

CVE-2025-9556

CVE-2025-9556 PUBLISHED CVSS 9.800000190734863 CRITICAL

Langchaingo supports the use of jinja2 syntax when parsing prompts, which is in turn parsed using the gonja library v1.5.3. Gonja supports include and extends syntax to read files, which leads to a server side template injection vulnerability within langchaingo, allowing an attacker to insert a statement into a prompt to read the "etc/passwd" file.

EPSS 0.12% · 29.9th percentile

Risk Scores

CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.12%
29.9th percentile

Affected Products

VendorProductVersions
LangchaingoLangchaingo0.1.14

Timeline

  • Sep 12, 2025 CVE Published
  • Sep 12, 2025 PoC Published
  • Sep 13, 2025 EPSS Score
  • Sep 15, 2025 PoC Published
  • Sep 15, 2025 PoC Published
  • Sep 20, 2025 EPSS Score
  • Sep 27, 2025 EPSS Score
  • Oct 5, 2025 EPSS Score
  • Oct 12, 2025 EPSS Score
  • Oct 19, 2025 EPSS Score
  • Oct 26, 2025 EPSS Score
  • Nov 2, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›