CVE-2024-38459: High severity pip/langchain-experimental vulnerability
Published Jun 16, 2024
·Updated
langchainexperimental (aka LangChain Experimental) before 0.0.61 for LangChain provides Python REPL access without an opt-in step. NOTE; this issue exists because of an incomplete fix for CVE-2024-27444.
Affected Software
2 affected componentsFixes available
pip/langchain-experimental<0.0.61
0.0.61
Langchain langchain-experimental<0.0.61
Remediation
Event History
Jun 16, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
RemedyAffected Software
Advisory Published
via GitHub·03:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-38459?
CVE-2024-38459 is classified as a medium severity vulnerability due to unauthorized access risks.
2
How do I fix CVE-2024-38459?
To fix CVE-2024-38459, upgrade the langchain-experimental package to version 0.0.61 or later.
3
What types of systems are affected by CVE-2024-38459?
CVE-2024-38459 affects systems that use the langchain-experimental package before version 0.0.61.
4
What does CVE-2024-38459 expose users to?
CVE-2024-38459 exposes users to potential unauthorized execution of Python code due to REPL access.
5
Is there a related CVE for CVE-2024-38459?
Yes, CVE-2024-38459 is related to CVE-2024-27444, which had an incomplete fix.