Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
langchain_experimental (aka LangChain Experimental) in LangChain before 0.0.306 allows an attacker to bypass the CVE-2023-36258 fix and execute arbitrary code via __import__ in Python code, which is not prohibited by pal_chain/base.py.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
LangChain 安全漏洞
Vulnerability Description
LangChain是通过可组合性使用 LLM 构建应用程序。 LangChain langchain_experimental 0.0.14版本存在安全漏洞,该漏洞源于允许攻击者绕过 CVE-2023-36258 修复,并通过 python exec 方法中的 PALChain 执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A