Last seen March 4, 2024

GitHub Remote Code Execution Vulnerability

Evidence indicates that GitHub is affected by remote code execution.

Technical Severity
Medium severity
Lifecycle Status

STABLE

What Happened

Evidence indicates that GitHub is affected by remote code execution.

Why This Matters

The evidence matters to defenders using GitHub because it could let an attacker run code in affected environments.

Recommended Action

No confirmed vendor remediation is available in the current evidence. Confirm whether GitHub is present in your environment and review the affected configuration.

Exposure

My Interests Exposure

Exposure unknown

Recommended Response
Last Seen

Mar 04, 2024 06:00

Exposure reason: This incident does not currently match a technology in My Interests.

Exploitation status: UNKNOWN

Primary entities:

GitHubRemote Code Executionvulnerabilitylangchain-ai/langchainlangchain

Timeline

  • Incident first seen
    Mar 04, 2024 06:00

    BugSkan first recorded this incident.

  • LangChain directory traversal vulnerability
    Mar 04, 2024 06:00

    GitHub Advisory Database · Vulnerability

Sources

LangChain directory traversal vulnerability

GitHub Advisory Database · Mar 04, 2024 06:00

LangChain through 0.1.10 allows ../ directory traversal by an actor who is able to control the final part of the path parameter in a load_chain call. This bypasses the intended behavior of loading configurations only from the hwchase17/langchain-hub GitHub repository. The outcome can be disclosure of an API key for a large language model online service, or remote code execution.

Open publisher source

My Interests Match

Want personalized relevance?

Create an account to see which incidents overlap with your interests.

← Back to incident intelligence