CVE-2023-36281: Code Injection
An issue in langchain v.0.0.171 allows a remote attacker to execute arbitrary code via a JSON file to loadprompt. This is related to subclasses or a template.
Other sources
An issue in langchain v.0.0.171 allows a remote attacker to execute arbitrary code via the via the a json file to the loadprompt parameter. This is related to subclasses or a template.
An issue in langchain v.0.0.171 allows a remote attacker to execute arbitrary code via the via the a json file to the loadprompt parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-36281?
CVE-2023-36281 is a vulnerability in langchain v.0.0.171 that allows a remote attacker to execute arbitrary code via a json file to the load_prompt parameter.
How severe is CVE-2023-36281?
CVE-2023-36281 has a severity level of critical with a CVSS score of 9.8.
Which software versions are affected by CVE-2023-36281?
CVE-2023-36281 affects langchain v.0.0.171.
How can the arbitrary code execution vulnerability in CVE-2023-36281 be exploited?
CVE-2023-36281 can be exploited by a remote attacker using a malicious json file as the load_prompt parameter.
Are there any references available for CVE-2023-36281?
Yes, references for CVE-2023-36281 can be found at the following links: [link1], [link2], [link3].