Harrison Chase · Langchain · CVE-2023-38896
**Name of the Vulnerable Software and Affected Versions**
Harrison Chase langchain versions 0.0.194 and before
Harrison Chase langchain versions prior to 0.0.236
**Description**
An issue in Harrison Chase langchain allows a remote attacker to execute arbitrary code via the `from math prompt` and `from colored object prompt` functions.
**Recommendations**
For versions 0.0.194 and before, update to version 0.0.236 or later to resolve the issue.
As a temporary workaround, consider disabling the `from math prompt` and `from colored object prompt` functions until a patch is available.