PT-2023-26641 · Langchain · Langchain

Boazwasserman

·

Publicado

2023-08-15

·

Atualizado

2023-08-22

·

CVE-2023-38860

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LangChain versions 0.0.231 through 0.0.246
Description An issue in LangChain allows a remote attacker to execute arbitrary code via the prompt parameter. This enables the attacker to potentially gain control over the system, leading to severe consequences.
Recommendations For LangChain versions 0.0.231 through 0.0.246, update to version 0.0.247 or later to resolve the issue. As a temporary workaround, consider restricting access to the prompt parameter to minimize the risk of exploitation.

Exploit

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-38860
GHSA-FJ32-Q626-PJJC
PYSEC-2023-145

Produtos afetados

Langchain