Safety vulnerability ID: 73298
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Affected versions of the langchain package are vulnerable to Deserialization of Untrusted Data due to unsafe pickle deserialization in the FAISS vector store implementation. The FAISS.deserialize_from_bytes function directly deserializes pickle data without proper validation, allowing arbitrary Python objects to be reconstructed and executed during the deserialization process.
Latest version: 0.3.29
Community contributed LangChain integrations.
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application