PT-2023-25510 · Langchain · Langchain

Obi1Kenobi

·

Published

2023-08-22

·

Updated

2024-10-15

·

CVE-2023-36281

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions langchain version 0.0.171
Description An issue in langchain allows a remote attacker to execute arbitrary code via a JSON file to the load prompt parameter. This is related to subclasses or a template.
Recommendations For langchain version 0.0.171, consider disabling the load prompt parameter until a patch is available to prevent remote attackers from executing arbitrary code. Restrict access to the load prompt function to minimize the risk of exploitation. Avoid using the load prompt parameter with JSON files from untrusted sources. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2023-36281
GHSA-7GFQ-F96F-G85J
PYSEC-2023-151

Affected Products

Langchain