Skip to content
LangChainGHSA-wmvm-9vqv-5qpp

langchain_experimental Code Execution via Python REPL access

High7.8CVE-2024-38459 · Published Jun 16, 2024 · updated Jul 5, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
langchain-experimental
PyPI
< 0.0.610.0.61
Details and references

langchain_experimental (aka LangChain Experimental) before 0.0.61 for LangChain provides Python REPL access without an opt-in step. NOTE; this issue exists because of an incomplete fix for CVE-2024-27444.

CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-276
Also known as
CVE-2024-38459, PYSEC-2024-53

More LangChain advisories

All LangChain
DateAdvisory
Jun 62024Denial of service in langchain-community
CVE-2024-2965Medium4.2fixed in 0.2.5
Jun 62024Server-Side Request Forgery in langchain-community.retrievers.web_research.WebResearchRetriever
CVE-2024-3095Medium4.8fixed in 0.2.9
Jul 152024langchain-experimental vulnerable to Arbitrary Code Execution
CVE-2024-21513Critical8.5fixed in 0.0.21
Apr 162024langchain vulnerable to path traversal
CVE-2024-3571Medium6.5fixed in 0.0.353
Mar 262024LangChain's XMLOutputParser vulnerable to XML Entity Expansion
CVE-2024-1455Medium5.9fixed in 0.1.35
Sep 172024LangChain pickle deserialization of untrusted data
CVE-2024-5998High5.2fixed in 0.2.4

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.