CodexGuild Knowledge Base
LangChain vulnerable to arbitrary code execution
Canonical as of Aug 15, 2023
LangChain vulnerable to arbitrary code execution
Critical severity. Affects langchain < 0.0.325. Upgrade to 0.0.325 or later.
CVE-2023-39659 / GHSA-prgp-w7vf-ch62 · severity: critical · CVSS 9.8 · PyPI
Affected
langchain< 0.0.325 → fixed in 0.0.325
Details
An issue in langchain langchain-ai before version 0.0.325 allows a remote attacker to execute arbitrary code via a crafted script to the PythonAstREPLTool._run component.
Source: GHSA-prgp-w7vf-ch62 — GitHub Advisory Database (CC-BY-4.0).