peter bassill · operator
$ cve CVE-2024-8309 JSON

CVE-2024-8309

9.8
CRITICAL · CVSS 3.1 · EPSS 13.7% (pctl 96)

Patch early

EPSS 13.7% — above the 10% action threshold.

Description

A vulnerability in the GraphCypherQAChain class of langchain-ai/langchain version 0.2.5 allows for SQL injection through prompt injection. This vulnerability can lead to unauthorized data manipulation, data exfiltration, denial of service (DoS) by deleting all data, breaches in multi-tenant security environments, and data integrity issues. Attackers can create, update, or delete nodes and relationships without proper authorization, extract sensitive data, disrupt services, access data across different tenants, and compromise the integrity of the database.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS13.74% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploitnone known
Published2024-10-29
Last modified2026-06-17

Affected (1)

VendorProduct
langchainlangchain

References

→ the Explorer  ·  watch your stack  ·  NVD