CodexGuild Knowledge Base
LangChain vulnerable to arbitrary code execution
Canonical as of Aug 15, 2023
LangChain vulnerable to arbitrary code execution
Critical severity. Affects langchain < 0.0.236. Upgrade to 0.0.236 or later.
CVE-2023-38896 / GHSA-92j5-3459-qgp4 · severity: critical · CVSS 9.8 · PyPI
Affected
langchain< 0.0.236 → fixed in 0.0.236
Details
An issue in Harrison Chase langchain before version 0.0.236 allows a remote attacker to execute arbitrary code via the from_math_prompt and from_colored_object_prompt functions.
Source: GHSA-92j5-3459-qgp4 — GitHub Advisory Database (CC-BY-4.0).