CodexGuild Knowledge Base
langchain Code Injection vulnerability
Canonical as of Aug 5, 2023
langchain Code Injection vulnerability
Critical severity. Affects langchain < 0.0.236. Upgrade to 0.0.236 or later.
CVE-2023-36095 / GHSA-gwqq-6vq7-5j86 · severity: critical · CVSS 9.8 · PyPI
Affected
langchain< 0.0.236 → fixed in 0.0.236
Details
An issue in Harrison Chase langchain allows an attacker to execute arbitrary code via the PALChain,from_math_prompt(llm).run in the python exec method.
Source: GHSA-gwqq-6vq7-5j86 — GitHub Advisory Database (CC-BY-4.0).