CVE-2023-36095: Code Injection
An issue in Harrison Chase langchain allows an attacker to execute arbitrary code via the PALChain,frommathprompt(llm).run in the python exec method.
Other sources
An issue in Harrison Chase langchain v.0.0.194 allows an attacker to execute arbitrary code via the PALChain,frommathprompt(llm).run in the python exec method.
An issue in Harrison Chase langchain v.0.0.194 allows an attacker to execute arbitrary code via the python exec calls in the PALChain, affected functions include frommathprompt and fromcoloredobjectprompt.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/langchainto a version that resolves this vulnerability.Fixed in 0.0.236
Event History
Frequently Asked Questions
What is CVE-2023-36095?
CVE-2023-36095 is an issue in Harrison Chase langchain v.0.0.194 that allows an attacker to execute arbitrary code via the python exec calls in the PALChain.
What functions are affected by CVE-2023-36095?
The affected functions include from_math_prompt and from_colored_object_prompt.
How severe is CVE-2023-36095?
CVE-2023-36095 has a severity rating of critical with a CVSS score of 9.8.
How can I fix CVE-2023-36095?
To fix CVE-2023-36095, update Harrison Chase langchain to version 0.0.236.
Where can I find more information about CVE-2023-36095?
You can find more information about CVE-2023-36095 on the GitHub page of Harrison Chase langchain (https://github.com/hwchase17/langchain) and the official website of langchain (http://langchain.com).