CVE-2023-36188: Critical severity Langchain Langchain vulnerability
An issue in langchain allows a remote attacker to execute arbitrary code via the PALChain parameter in the Python exec method.
Other sources
An issue in langchain v.0.0.64 allows a remote attacker to execute arbitrary code via the PALChain parameter in the Python exec method.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/langchainto a version that resolves this vulnerability.Fixed in 0.0.236
Event History
Frequently Asked Questions
What is the severity of CVE-2023-36188?
CVE-2023-36188 is classified as a critical vulnerability due to its ability to allow remote code execution.
How do I fix CVE-2023-36188?
To mitigate CVE-2023-36188, upgrade langchain to a version greater than 0.0.236.
What is affected by CVE-2023-36188?
CVE-2023-36188 affects langchain version 0.0.64 and earlier releases.
Can CVE-2023-36188 be exploited remotely?
Yes, CVE-2023-36188 can be exploited by remote attackers through the PALChain parameter.
What programming languages are impacted by CVE-2023-36188?
CVE-2023-36188 specifically impacts Python applications using the langchain library.