CodexGuild Knowledge Base
LangChain vulnerable to code injection
Canonical as of Apr 5, 2023
LangChain vulnerable to code injection
Critical severity. Affects langchain <= 0.0.131. No patched version yet.
CVE-2023-29374 / GHSA-fprp-p869-w6q2 · severity: critical · CVSS 9.8 · PyPI
Affected
langchain<= 0.0.131 (no fix yet)
Details
In LangChain through 0.0.131, the LLMMathChain chain allows prompt injection attacks that can execute arbitrary code via the Python exec() method.
Source: GHSA-fprp-p869-w6q2 — GitHub Advisory Database (CC-BY-4.0).