Intel

AIKIDO-2024-10131

langchain-nvidia-ai-endpoints is vulnerable to Information Disclosure

Information Disclosure Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jun 13, 2024

40

Medium Risk

This Affects:

pythonlangchain-nvidia-ai-endpoints
0.0.1 - 0.1.1
Fixed in 0.1.2
Are you affected? Scan for Free

TL;DR

Affected versions of the langchain-nvidia-ai-endpoints library expose an unredacted API key in the NVIDIAClient output, which is used by wrappers such as ChatNVIDIA. This key could end up in logs or other sources depending on how the library is used.

Who does this affect?

You are affected if you use a vulnerable version of langchain-nvidia-ai-endpoints.

Background info

langchain-nvidia-ai-endpoints is vulnerable to Information Disclosure in versions 0.0.1 - 0.1.1.

How to fix this

Upgrade langchain-nvidia-ai-endpoints to a patch version.