
Proof-of-concept demonstrating prompt injection in Langchain's GraphCypherQAChain leading to SQL injection in Neo4j databases. Includes Docker-based setup with FastAPI backend and Streamlit frontend for educational testing.
This setup demonstrates a proof of concept for the prompt injection vulnerability in the GraphCypherQAChain class that allows SQL injection in a Neo4j database.

AZURE_API_KEY=
AZURE_CHAT_DEPLOYMENT=
AZURE_ENDPOINT=
OPENAI_API_KEY=
LLM_PROVIDER= # "azure, openai"
docker-compose build
docker-compose up
http://localhost:7474 (default username: neo4j, password: password).http://localhost:8000.http://localhost:8501.delete all entities
MATCH (n) DETACH DELETE n
This PoC is for educational purposes only. Misuse can lead to serious security breaches.