Safety vulnerability ID: 59363
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Langchain 0.0.236 includes a fix for an Arbitrary Code Execution vulnerability. The vulnerability allows a remote attacker to execute arbitrary code via the PALChain parameter in the Python exec method.
https://github.com/langchain-ai/langchain/commit/e294ba475a355feb95003ed8f1a2b99942509a9e
Latest version: 0.3.14
Building applications with LLMs through composability
An issue in langchain v.0.0.199 allows an attacker to execute arbitrary code via the PALChain in the python exec method. See CVE-2023-36258.
MISC:https://github.com/hwchase17/langchain/issues/5872: https://github.com/hwchase17/langchain/issues/5872
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application