Safety vulnerability ID: 60433
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Affected versions of langchain allow a remote attacker to execute arbitrary code via a crafted script to the PythonAstREPLTool._run component.
#NOTE: The data we include in this advisory differs from the publicly available on nvd.nist.gov. The advisory posted by the NVD indicated that versions up to and including 0.0.232 were affected. However, research by Safety CLI Cybersecurity confirms that the vulnerability remains unaddressed in all versions up to 0.0.325.
Latest version: 0.3.14
Building applications with LLMs through composability
An issue in langchain langchain-ai v.0.0.232 and before allows a remote attacker to execute arbitrary code via a crafted script to the PythonAstREPLTool._run component. See CVE-2023-39659.
MISC:https://github.com/langchain-ai/langchain/issues/7700: https://github.com/langchain-ai/langchain/issues/7700
MISC:https://github.com/langchain-ai/langchain/pull/5640: https://github.com/langchain-ai/langchain/pull/5640
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application