CVE-2023-44467: Critical severity Langchain Langchain Experimental Python vulnerability
langchainexperimental (aka LangChain Experimental) in LangChain before 0.0.306 allows an attacker to bypass the CVE-2023-36258 fix and execute arbitrary code via import in Python code, which is not prohibited by palchain/base.py.
Other sources
langchainexperimental 0.0.14 allows an attacker to bypass the CVE-2023-36258 fix and execute arbitrary code via the PALChain in the python exec method.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-44467?
CVE-2023-44467 is a vulnerability in langchain_experimental 0.0.14 that allows an attacker to bypass a previous fix and execute arbitrary code.
How does CVE-2023-44467 work?
CVE-2023-44467 works by exploiting the PALChain in the python exec method.
Is langchain_experimental 0.0.14 affected by this vulnerability?
Yes, langchain_experimental 0.0.14 is affected by CVE-2023-44467.
What is the severity of CVE-2023-44467?
The severity of CVE-2023-44467 is not specified in the provided information.
How can I fix CVE-2023-44467?
To fix CVE-2023-44467, update langchain_experimental to a version that includes the fix or apply the relevant patch provided by the vendor.