Skip to content
LangChainGHSA-fprp-p869-w6q2

LangChain vulnerable to code injection

Critical9.8CVE-2023-29374 · Published Apr 5, 2023 · updated Feb 12, 2025

GitHub advisory

Affected versions

PackageAffectedFixed in
langchain
PyPI
<= 0.0.131No fix yet
Details and references

In LangChain through 0.0.131, the `LLMMathChain` chain allows prompt injection attacks that can execute arbitrary code via the Python `exec()` method.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-74, CWE-94
Also known as
CVE-2023-29374, PYSEC-2023-18

More LangChain advisories

All LangChain
DateAdvisory
Jun 142023Langchain OS Command Injection vulnerability
CVE-2023-34540Critical9.8fixed in 0.0.225
Jun 202023Langchain vulnerable to arbitrary code execution
CVE-2023-34541Critical9.8fixed in 0.0.247
Jul 32023langchain arbitrary code execution vulnerability
CVE-2023-36258Critical9.8fixed in 0.0.247
Jul 62023langchain vulnerable to arbitrary code execution
CVE-2023-36188Critical9.8fixed in 0.0.247
Jul 62023langchain SQL Injection vulnerability
CVE-2023-36189High7.5fixed in 0.0.247
Aug 52023langchain Code Injection vulnerability
CVE-2023-36095Critical9.8fixed in 0.0.236

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.