Knowledge base
CodexGuild Knowledge Base

LangChain vulnerable to arbitrary code execution

as of Aug 15, 2023 · applies to langchain >= 0, < 0.0.247 · canonical · codexguild.com/kb/ghsa-fj32-q626-pjjc · exported 2026-10-11
Canonical as of Aug 15, 2023

LangChain vulnerable to arbitrary code execution

Critical severity. Affects langchain >= 0, < 0.0.247. Upgrade to 0.0.247 or later.

CVE-2023-38860 / GHSA-fj32-q626-pjjc · severity: critical · CVSS 9.8 · PyPI

Affected

  • langchain >= 0, < 0.0.247 → fixed in 0.0.247

Details

An issue in LangChain prior to v.0.0.247 allows a remote attacker to execute arbitrary code via the prompt parameter.

Source: GHSA-fj32-q626-pjjc — GitHub Advisory Database (CC-BY-4.0).