CVE-2023-38860: Code Injection
Published Aug 15, 2023
·Updated
An issue in LangChain prior to v.0.0.247 allows a remote attacker to execute arbitrary code via the prompt parameter.
Other sources
An issue in LangChain v.0.0.231 allows a remote attacker to execute arbitrary code via the prompt parameter.
Affected Software
2 affected componentsFixes available
pip/langchain>=0<0.0.247
0.0.247
Langchain Langchain=0.0.231
Event History
Aug 15, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Advisory Published
06:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2023-38860?
The severity of CVE-2023-38860 is critical with a CVSS score of 9.8.
2
What is the affected software for CVE-2023-38860?
The affected software for CVE-2023-38860 is LangChain v.0.0.231.
3
How can a remote attacker exploit CVE-2023-38860?
A remote attacker can exploit CVE-2023-38860 by executing arbitrary code via the prompt parameter.
4
Is there a fix available for CVE-2023-38860?
Please refer to the vendor's advisory for information on the fix for CVE-2023-38860.
5
Where can I find more information about CVE-2023-38860?
You can find more information about CVE-2023-38860 on the NIST National Vulnerability Database (NVD) and the GitHub repository for LangChain.