Sploitus

CVE-2025-2828

No indexed exploits for CVE-2025-2828 yet

A Server-Side Request Forgery (SSRF) vulnerability exists in the RequestsToolkit component of the langchain-community package (specifically, langchain_community.agent_toolkits.openapi.toolkit.RequestsToolkit) in langchain-ai/langchain version 0.0.27. This vulnerability occurs because the toolkit does not enforce restrictions on requests to remote internet addresses, allowing it to also access local addresses. As a result, an attacker could exploit this flaw to perform port scans, access local services, retrieve instance metadata from cloud environments (e.g., Azure, AWS), and interact with servers on the local network. This issue has been fixed in version 0.0.28.

Affected products
Langchain
Langchain
< 0.0.28
Fix
Available
CVSS 3.1
10.0 CRITICAL
EPSS
15.9% (97th percentile)
Weakness
CWE-918
NVD status
Analyzed
Published
2025-06-23
CVE-2025-2828 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2025-2828 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2025-2828 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.