CVE-2023-34541: Critical severity Langchain Langchain vulnerability
Published Jun 20, 2023
·Updated
Langchain 0.0.171 is vulnerable to Arbitrary code execution in loadprompt.
Other sources
Langchain 0.0.171 is vulnerable to Arbitrary code execution in loadprompt.
Affected Software
2 affected componentsFixes available
pip/langchain<0.0.247
0.0.247
Langchain Langchain=0.0.171
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/langchainto a version that resolves this vulnerability.Fixed in 0.0.247
Event History
Jun 20, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityAffected Software
Advisory Published
via GitHub·03:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2023-34541?
CVE-2023-34541 is considered a high severity vulnerability due to the potential for arbitrary code execution.
2
How do I fix CVE-2023-34541?
To mitigate CVE-2023-34541, upgrade langchain to version 0.0.247 or later.
3
Which software versions are affected by CVE-2023-34541?
CVE-2023-34541 affects langchain version 0.0.171.
4
What type of vulnerability is CVE-2023-34541?
CVE-2023-34541 is characterized as an arbitrary code execution vulnerability.
5
Can CVE-2023-34541 be exploited remotely?
Yes, CVE-2023-34541 can be exploited remotely if an attacker can trigger the vulnerable `load_prompt` function.