Knowledge base
CodexGuild Knowledge Base

LangChain vulnerable to arbitrary code execution

as of Aug 15, 2023 · applies to langchain < 0.0.236 · canonical · codexguild.com/kb/ghsa-92j5-3459-qgp4 · exported 2026-10-11
Canonical as of Aug 15, 2023

LangChain vulnerable to arbitrary code execution

Critical severity. Affects langchain < 0.0.236. Upgrade to 0.0.236 or later.

CVE-2023-38896 / GHSA-92j5-3459-qgp4 · severity: critical · CVSS 9.8 · PyPI

Affected

  • langchain < 0.0.236 → fixed in 0.0.236

Details

An issue in Harrison Chase langchain before version 0.0.236 allows a remote attacker to execute arbitrary code via the from_math_prompt and from_colored_object_prompt functions.

Source: GHSA-92j5-3459-qgp4 — GitHub Advisory Database (CC-BY-4.0).