Knowledge base
CodexGuild Knowledge Base

Langchain vulnerable to arbitrary code execution via the evaluate function in the numexpr library

as of Sep 1, 2023 · applies to langchain < 0.0.308 · canonical · codexguild.com/kb/ghsa-f73w-4m7g-ch9x · exported 2026-10-11
Canonical as of Sep 1, 2023

Langchain vulnerable to arbitrary code execution via the evaluate function in the numexpr library

Critical severity. Affects langchain < 0.0.308. Upgrade to 0.0.308 or later.

CVE-2023-39631 / GHSA-f73w-4m7g-ch9x · severity: critical · CVSS 9.8 · PyPI

Affected

  • langchain < 0.0.308 → fixed in 0.0.308

Details

An issue in LanChain-ai Langchain v.0.0.245 allows a remote attacker to execute arbitrary code via the evaluate function in the numexpr library.

Patches: Released in v.0.0.308. numexpr dependency is optional for langchain.

Source: GHSA-f73w-4m7g-ch9x — GitHub Advisory Database (CC-BY-4.0).