Safety vulnerability ID: 79462
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Affected versions of the langchain-community package are vulnerable to XML External Entity (XXE) Injection due to the use of `etree.iterparse` without disabling external entity resolution. ([GitHub][1]) The `langchain_community.document_loaders.evernote` module’s `EverNoteLoader` parses ENEX input with `etree.iterparse()` without a hardened XML parser, enabling expansion of external entities and unintended access to local resources.
Latest version: 0.3.29
Community contributed LangChain integrations.
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application