CodexGuild Knowledge Base
langchain vulnerable to arbitrary code execution
Canonical as of Jul 6, 2023
langchain vulnerable to arbitrary code execution
Critical severity. Affects langchain < 0.0.247. Upgrade to 0.0.247 or later.
CVE-2023-36188 / GHSA-57fc-8q82-gfp3 · severity: critical · CVSS 9.8 · PyPI
Affected
langchain< 0.0.247 → fixed in 0.0.247
Details
An issue in langchain allows a remote attacker to execute arbitrary code via the PALChain parameter in the Python exec method.
Source: GHSA-57fc-8q82-gfp3 — GitHub Advisory Database (CC-BY-4.0).