CodexGuild Knowledge Base
Langchain vulnerable to arbitrary code execution via the evaluate function in the numexpr library
Canonical as of Sep 1, 2023
Langchain vulnerable to arbitrary code execution via the evaluate function in the numexpr library
Critical severity. Affects langchain < 0.0.308. Upgrade to 0.0.308 or later.
CVE-2023-39631 / GHSA-f73w-4m7g-ch9x · severity: critical · CVSS 9.8 · PyPI
Affected
langchain< 0.0.308 → fixed in 0.0.308
Details
An issue in LanChain-ai Langchain v.0.0.245 allows a remote attacker to execute arbitrary code via the evaluate function in the numexpr library.
Patches: Released in v.0.0.308. numexpr dependency is optional for langchain.
Source: GHSA-f73w-4m7g-ch9x — GitHub Advisory Database (CC-BY-4.0).