Description
An issue in LanChain-ai Langchain v.0.0.245 allows a remote attacker to execute arbitrary code via the evaluate function in the numexpr library.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0117 | Langchain vulnerable to arbitrary code execution via the evaluate function in the numexpr library |
Github GHSA |
GHSA-f73w-4m7g-ch9x | Langchain vulnerable to arbitrary code execution via the evaluate function in the numexpr library |
References
History
Tue, 01 Oct 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-10-01T13:18:38.891Z
Reserved: 2023-08-07T00:00:00.000Z
Link: CVE-2023-39631
Updated: 2024-08-02T18:18:09.557Z
Status : Modified
Published: 2023-09-01T16:15:08.370
Modified: 2024-11-21T08:15:43.510
Link: CVE-2023-39631
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA