A vulnerability in the FAISS.deserialize_from_bytes function of langchain-ai/langchain allows for pickle deserialization of untrusted data. This can lead to the execution of arbitrary commands via the os.system function. The issue affects the latest version of the product.
Metrics
Affected Vendors & Products
References
History
Tue, 17 Sep 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Langchain
Langchain langchain |
|
CPEs | cpe:2.3:a:langchain:langchain:*:*:*:*:*:*:*:* | |
Vendors & Products |
Langchain
Langchain langchain |
|
Metrics |
ssvc
|
Tue, 17 Sep 2024 12:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability in the FAISS.deserialize_from_bytes function of langchain-ai/langchain allows for pickle deserialization of untrusted data. This can lead to the execution of arbitrary commands via the os.system function. The issue affects the latest version of the product. | |
Title | Deserialization of Untrusted Data in langchain-ai/langchain | |
Weaknesses | CWE-502 | |
References |
| |
Metrics |
cvssV3_0
|
MITRE
Status: PUBLISHED
Assigner: @huntr_ai
Published: 2024-09-17T11:50:13.813Z
Updated: 2024-09-17T13:34:15.648Z
Reserved: 2024-06-14T13:32:32.118Z
Link: CVE-2024-5998
Vulnrichment
Updated: 2024-09-17T13:34:10.374Z
NVD
Status : Awaiting Analysis
Published: 2024-09-17T12:15:02.977
Modified: 2024-09-20T12:31:20.110
Link: CVE-2024-5998
Redhat
No data.