Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!
CVE-2024-8309 — Proof-of-concept che dimostra l'iniezione di prompt nella GraphCypherQAChain di Langchain, che porta a un'iniezione SQL nei database Neo4j. Include una configurazione basata su Docker con backend FastAPI e frontend Streamlit per test didattici. | Kitploit
Proof-of-concept che dimostra l'iniezione di prompt nella GraphCypherQAChain di Langchain, che porta a un'iniezione SQL nei database Neo4j. Include una configurazione basata su Docker con backend FastAPI e frontend Streamlit per test didattici.
Proof of Concept per la vulnerabilità CVE-2024–8309 di Langchain
Panoramica
Questa configurazione dimostra un proof of concept per la vulnerabilità di iniezione di prompt nella classe GraphCypherQAChain che consente l'iniezione SQL in un database Neo4j.
Componenti:
Database Neo4j: Esegue Neo4j.
Backend (FastAPI): Interagisce con Neo4j usando Langchain.
Frontend (Streamlit): Interfaccia semplice per interagire con il backend.