Knowledge base
CodexGuild Knowledge Base

LangChain vulnerable to code injection

as of Apr 5, 2023 · applies to langchain <= 0.0.131 · canonical · codexguild.com/kb/ghsa-fprp-p869-w6q2 · exported 2026-10-11
Canonical as of Apr 5, 2023

LangChain vulnerable to code injection

Critical severity. Affects langchain <= 0.0.131. No patched version yet.

CVE-2023-29374 / GHSA-fprp-p869-w6q2 · severity: critical · CVSS 9.8 · PyPI

Affected

  • langchain <= 0.0.131 (no fix yet)

Details

In LangChain through 0.0.131, the LLMMathChain chain allows prompt injection attacks that can execute arbitrary code via the Python exec() method.

Source: GHSA-fprp-p869-w6q2 — GitHub Advisory Database (CC-BY-4.0).