CVE-2023-36258: Code Injection
An issue in langchain allows an attacker to execute arbitrary code via the PALChain in the python exec method.
Other sources
An issue in LangChain before 0.0.236 allows an attacker to execute arbitrary code because Python code with os.system, exec, or eval can be used.
— MITRE
An issue in langchain v.0.0.199 allows an attacker to execute arbitrary code via the PALChain in the python exec method.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/langchainto a version that resolves this vulnerability.Fixed in 0.0.247
Event History
Frequently Asked Questions
What is the severity of CVE-2023-36258?
CVE-2023-36258 is classified with a high severity due to the potential for arbitrary code execution.
How do I fix CVE-2023-36258?
To fix CVE-2023-36258, update to langchain version 0.0.247 or later.
What versions of langchain are affected by CVE-2023-36258?
CVE-2023-36258 affects langchain versions prior to 0.0.247, specifically version 0.0.199.
What kind of attacks does CVE-2023-36258 enable?
CVE-2023-36258 enables attackers to execute arbitrary code using Python commands like os.system, exec, or eval.
Which software is impacted by CVE-2023-36258?
CVE-2023-36258 impacts the langchain software package from versions earlier than 0.0.247.