GitHub Remote Code Execution Vulnerability
Evidence indicates that GitHub is affected by remote code execution.
STABLE
What Happened
Evidence indicates that GitHub is affected by remote code execution.
Why This Matters
The evidence matters to defenders using GitHub because it could let an attacker run code in affected environments.
Recommended Action
No confirmed vendor remediation is available in the current evidence. Confirm whether GitHub is present in your environment and review the affected configuration.
Exposure
Exposure unknown
Mar 04, 2024 06:00
Exposure reason: This incident does not currently match a technology in My Interests.
Exploitation status: UNKNOWN
Primary entities:
Timeline
-
Incident first seen
Mar 04, 2024 06:00BugSkan first recorded this incident.
-
LangChain directory traversal vulnerability
Mar 04, 2024 06:00GitHub Advisory Database · Vulnerability
Sources
GitHub Advisory Database · Mar 04, 2024 06:00
LangChain through 0.1.10 allows ../ directory traversal by an actor who is able to control the final part of the path parameter in a load_chain call. This bypasses the intended behavior of loading configurations only from the hwchase17/langchain-hub GitHub repository. The outcome can be disclosure of an API key for a large language model online service, or remote code execution.
Open publisher sourceMy Interests Match
Create an account to see which incidents overlap with your interests.