PT-2023-26641 · Langchain · Langchain

Boazwasserman

·

Published

2023-08-15

·

Updated

2023-08-22

·

CVE-2023-38860

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LangChain versions 0.0.231 through 0.0.246
Description An issue in LangChain allows a remote attacker to execute arbitrary code via the prompt parameter. This enables the attacker to potentially gain control over the system, leading to severe consequences.
Recommendations For LangChain versions 0.0.231 through 0.0.246, update to version 0.0.247 or later to resolve the issue. As a temporary workaround, consider restricting access to the prompt parameter to minimize the risk of exploitation.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2023-38860
GHSA-FJ32-Q626-PJJC
PYSEC-2023-145

Affected Products

Langchain