Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Corgeman

#23352of 53,622
10Total CVSS
Vulnerabilities · 1
PT-2023-27040
10
2023-01-09
Numexpr · Numexpr · CVE-2023-39631
**Name of the Vulnerable Software and Affected Versions** LangChain versions 0.0.245 through 0.0.307 **Description** The issue is related to incorrect code generation control in the numexpr library of the LangChain framework, allowing a remote attacker to execute arbitrary code via the `evaluate` function. This can lead to exploitation by a remote attacker. **Recommendations** For versions 0.0.245 through 0.0.307, update to version 0.0.308 or later, which includes a patch for the numexpr dependency issue. As a temporary workaround, consider disabling the `evaluate` function in the numexpr library until a patch is applied.