HaystackGHSA-w7qg-j435-78qw
Use of hard-coded, security-relevant constants in deepset-ai/haystack
Critical9.8CVE-2023-1712 · Published Mar 30, 2023 · updated Jun 29, 2026
Use of Hard-coded, Security-relevant Constants in GitHub repository deepset-ai/haystack in version 1.15.0 and prior. A patch is available at commit 5fc84904f198de661d5b933fde756aa922bf09f1.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| farm-haystack PyPI | <= 1.15.0 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-547
- Also known as
- CVE-2023-1712, PYSEC-2026-337
More Haystack advisories
All Haystack| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 312024 | Insecure Jinja2 templates rendered in Haystack Components can lead to RCE | High7.5 | 2.3.1 |