Skip to content
LangChainGHSA-x32c-59v5-h7fg

Langchain OS Command Injection vulnerability

Critical9.8CVE-2023-34540 · Published Jun 14, 2023 · updated Feb 21, 2025

Langchain before v0.0.225 was discovered to contain a remote code execution (RCE) vulnerability in the component JiraAPIWrapper (aka the JIRA API wrapper). This vulnerability allows attackers to execute arbitrary code via crafted input. As noted in the "releases/tag" reference, a fix is available.

GitHub advisory

Affected versions

PackageAffectedFixed in
langchain
PyPI
< 0.0.2250.0.225
Details and references

More LangChain advisories

All LangChain
Advisory
LangChain vulnerable to arbitrary code execution
Critical9.8Aug 15, 2023
langchain Code Injection vulnerability
Critical9.8Aug 5, 2023
langchain SQL Injection vulnerability
High7.5Jul 6, 2023
langchain vulnerable to arbitrary code execution
Critical9.8Jul 6, 2023
langchain arbitrary code execution vulnerability
Critical9.8Jul 3, 2023
Langchain vulnerable to arbitrary code execution
Critical9.8Jun 20, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.