SSRF vulnerability in unstructured library URL handling
The unstructured library contains a server-side request forgery vulnerability in its URL-based partitioning functions that allows attackers to read responses from internal services and cloud metadata endpoints. The vulnerability affects the partition(), partition_html(), and partition_md() functions and has been present since version 0.4.7 without host validation.
Disclosed 3 September 2026 · Record updated 13 September 2026
Impact
Attackers can exploit the SSRF to reach loopback admin APIs, internal HTTP services, and cloud metadata endpoints, reading sensitive response data. The vulnerability affects downstream users of LangChain UnstructuredURLLoader, LlamaIndex UnstructuredReader, Chainlit, and many agent frameworks.
Our coverage
No articles linked to this incident yet.
Sources
- github.comhttps://github.com/advisories/GHSA-4mvj-m6j5-pmf7
