Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-2828

35
FAUCET Score

CVE-2025-2828 is a critical Server-Side Request Forgery (SSRF) vulnerability in the RequestsToolkit component of the langchain-community package (langchain-ai/langchain version 0.0.27). This flaw allows an attacker to bypass restrictions on remote requests, enabling access to local network resources, port scanning, and retrieval of sensitive cloud instance metadata. With a CVSS score of 10.0 (CRITICAL), the vulnerability is easily exploitable over the network with no user interaction, leading to complete compromise of confidentiality, integrity, and availability. While no active exploitation, public exploit code, or significant community discussion has been observed, the high FAUCET Risk Score of 88/100 indicates its severe potential.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.0.28CPE matchmatch criteria
cpe:2.3:a:langchain:langchain:*:*:*:*:community:*:*:*

CVSS Data

CVSS version used by this source: 3.0

8.4HIGH

CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.7
Impact Score
6.0
CvssVersion
3.0

Exploit Intelligence

EPSS Score
14.73%
Probability of exploitation in next 30 days
EPSS Percentile
96.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.1473 is in the 92nd percentile among its peer group of 36,833 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
pippatch availablevia ghsa
Product: langchain-communityFixed in: 0.0.28

Vendor Advisories (2)

pipGHSA-h5gc-rm8j-5gprhigh

LangChain Community SSRF vulnerability exists in RequestsToolkit component

Jun 23, 2025
redhatCVE-2025-2828Important

langchain-community: SSRF Vulnerability in langchain-community

Jun 23, 2025

References

github.com / langchain-ai/langchain/commit/e188d4ecb085d4561a0be3c583d26aa9c2c3283f
Patch
huntr.com / bounties/8f771040-7f34-420a-b96b-5b93d4a99afc
ExploitThird Party Advisory