Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0

Affected products and versions

1 source assertion
{"product":"langchain4j","vendor":"langchain4j","versions":[{"status":"affected","version":"< 1.2.1-beta8"},{"status":"affected","version":">= 1.3.0-beta9, < 1.5.1-beta11"},{"status":"affected","version":">= 1.6.0-beta12, < 1.11.8-beta19"},{"status":"affected","version":">= 1.12.1-beta21, < 1.16.3-beta26"}]}
  • cve_program_cvelist_v5affected
    urn:baitaphish:normalized-source-record:v2:699ed73210eb3c9c7c3225dc1b8e9ce4ce646c5634b74d30a889ace2e8b42201 · sha256:ac576742a1b6325d… · /containers/cna/affected/0

Provider-owned CVSS observations

1 source assertion
{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":7.6,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L","version":"3.1"},"metric_type":"cvssV3_1"}
  • cve_program_cvelist_v5cvss
    urn:baitaphish:normalized-source-record:v2:699ed73210eb3c9c7c3225dc1b8e9ce4ce646c5634b74d30a889ace2e8b42201 · sha256:ac576742a1b6325d… · /containers/cna/metrics/0/cvssV3_1

CWE assertions

1 source assertion
{"cweId":"CWE-89","description":"CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","lang":"en","type":"CWE"}
  • cve_program_cvelist_v5cwe
    urn:baitaphish:normalized-source-record:v2:699ed73210eb3c9c7c3225dc1b8e9ce4ce646c5634b74d30a889ace2e8b42201 · sha256:ac576742a1b6325d… · /containers/cna/problemTypes/0/descriptions/0

Source references

7 source assertions
{"name":"https://github.com/langchain4j/langchain4j/commit/13a0698bdfaf105d8aaf0367881df51358596219","tags":["x_refsource_MISC"],"url":"https://github.com/langchain4j/langchain4j/commit/13a0698bdfaf105d8aaf0367881df51358596219"}
  • cve_program_cvelist_v5reference
    urn:baitaphish:normalized-source-record:v2:699ed73210eb3c9c7c3225dc1b8e9ce4ce646c5634b74d30a889ace2e8b42201 · sha256:ac576742a1b6325d… · /containers/cna/references/1
{"name":"https://github.com/langchain4j/langchain4j/commit/1bc1f60aa58ef5c3c1703caf73362482480351cf","tags":["x_refsource_MISC"],"url":"https://github.com/langchain4j/langchain4j/commit/1bc1f60aa58ef5c3c1703caf73362482480351cf"}
  • cve_program_cvelist_v5reference
    urn:baitaphish:normalized-source-record:v2:699ed73210eb3c9c7c3225dc1b8e9ce4ce646c5634b74d30a889ace2e8b42201 · sha256:ac576742a1b6325d… · /containers/cna/references/2
{"name":"https://github.com/langchain4j/langchain4j/commit/8805d5d128694302f1b0a2650174186862f669e7","tags":["x_refsource_MISC"],"url":"https://github.com/langchain4j/langchain4j/commit/8805d5d128694302f1b0a2650174186862f669e7"}
  • cve_program_cvelist_v5reference
    urn:baitaphish:normalized-source-record:v2:699ed73210eb3c9c7c3225dc1b8e9ce4ce646c5634b74d30a889ace2e8b42201 · sha256:ac576742a1b6325d… · /containers/cna/references/3
{"name":"https://github.com/langchain4j/langchain4j/commit/ce96291dfb243c7f6753b5d65c7a77914642314f","tags":["x_refsource_MISC"],"url":"https://github.com/langchain4j/langchain4j/commit/ce96291dfb243c7f6753b5d65c7a77914642314f"}
  • cve_program_cvelist_v5reference
    urn:baitaphish:normalized-source-record:v2:699ed73210eb3c9c7c3225dc1b8e9ce4ce646c5634b74d30a889ace2e8b42201 · sha256:ac576742a1b6325d… · /containers/cna/references/4
{"name":"https://github.com/langchain4j/langchain4j/commit/f14a10ce77e4ea1b8277f67d6a81f46abd7a5bc2","tags":["x_refsource_MISC"],"url":"https://github.com/langchain4j/langchain4j/commit/f14a10ce77e4ea1b8277f67d6a81f46abd7a5bc2"}
  • cve_program_cvelist_v5reference
    urn:baitaphish:normalized-source-record:v2:699ed73210eb3c9c7c3225dc1b8e9ce4ce646c5634b74d30a889ace2e8b42201 · sha256:ac576742a1b6325d… · /containers/cna/references/5
{"name":"https://github.com/langchain4j/langchain4j/releases/tag/1.16.3","tags":["x_refsource_MISC"],"url":"https://github.com/langchain4j/langchain4j/releases/tag/1.16.3"}
  • cve_program_cvelist_v5reference
    urn:baitaphish:normalized-source-record:v2:699ed73210eb3c9c7c3225dc1b8e9ce4ce646c5634b74d30a889ace2e8b42201 · sha256:ac576742a1b6325d… · /containers/cna/references/6
{"name":"https://github.com/langchain4j/langchain4j/security/advisories/GHSA-2mfg-cc43-9pcj","tags":["x_refsource_CONFIRM"],"url":"https://github.com/langchain4j/langchain4j/security/advisories/GHSA-2mfg-cc43-9pcj"}
  • cve_program_cvelist_v5reference
    urn:baitaphish:normalized-source-record:v2:699ed73210eb3c9c7c3225dc1b8e9ce4ce646c5634b74d30a889ace2e8b42201 · sha256:ac576742a1b6325d… · /containers/cna/references/0

Attribution and limitations

  • CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →

Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.