CVE Vulnerabilities

CVE-2023-36258

Published: Jul 03, 2023 | Modified: Feb 26, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An issue in LangChain before 0.0.236 allows an attacker to execute arbitrary code because Python code with os.system, exec, or eval can be used.

Affected Software

Name Vendor Start Version End Version
Langchain Langchain 0.0.199 (including) 0.0.199 (including)

References