CVE Vulnerabilities

CVE-2023-36258

Published: Jul 03, 2023 | Modified: Nov 22, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An issue in LangChain before 0.0.236 allows an attacker to execute arbitrary code because Python code with os.system, exec, or eval can be used.

Affected Software

NameVendorStart VersionEnd Version
LangchainLangchain0.0.199 (including)0.0.199 (including)

References