CVE-2023-39659: Critical severity langchain vulnerability
An issue in langchain langchain-ai before version 0.0.325 allows a remote attacker to execute arbitrary code via a crafted script to the PythonAstREPLTool.run component.
Other sources
An issue in langchain langchain-ai v.0.0.232 and before allows a remote attacker to execute arbitrary code via a crafted script to the PythonAstREPLTool.run component.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-39659?
CVE-2023-39659 is classified as a high-severity vulnerability that allows remote code execution.
How do I fix CVE-2023-39659?
To fix CVE-2023-39659, upgrade to langchain version 0.0.325 or later.
What components are impacted by CVE-2023-39659?
CVE-2023-39659 affects the PythonAstREPLTool._run component in langchain versions prior to 0.0.325.
Can I continue using langchain versions before 0.0.325 without any risk?
Using langchain versions before 0.0.325 poses a significant risk due to the potential for arbitrary code execution.
What type of attacks can be executed using CVE-2023-39659?
CVE-2023-39659 allows remote attackers to execute arbitrary scripts, leading to potential system compromise.