VDB
CVE-2025-9556
CVE-2025-9556
PUBLISHED
CVSS 9.800000190734863 CRITICAL
Langchaingo supports the use of jinja2 syntax when parsing prompts, which is in turn parsed using the gonja library v1.5.3. Gonja supports include and extends syntax to read files, which leads to a server side template injection vulnerability within langchaingo, allowing an attacker to insert a statement into a prompt to read the "etc/passwd" file.
EPSS 0.12% · 29.9th percentile
Risk Scores
CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.12%
29.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Langchaingo | Langchaingo | 0.1.14 |
Timeline
- Sep 12, 2025 CVE Published
- Sep 12, 2025 PoC Published
- Sep 13, 2025 EPSS Score
- Sep 15, 2025 PoC Published
- Sep 15, 2025 PoC Published
- Sep 20, 2025 EPSS Score
- Sep 27, 2025 EPSS Score
- Oct 5, 2025 EPSS Score
- Oct 12, 2025 EPSS Score
- Oct 19, 2025 EPSS Score
- Oct 26, 2025 EPSS Score
- Nov 2, 2025 EPSS Score