AI Remote Code Execution Vulnerability
An issue in langchain v.0.0.171 allows a remote attacker to execute arbitrary code via the via the a json file to the `load_prompt` parameter. This is related to `__subclasses__` or a template.
What Happened
An issue in langchain v.0.0.171 allows a remote attacker to execute arbitrary code via the via the a json file to the `load_prompt` parameter. This is related to `__subclasses__` or a template.
Why This Matters
Current evidence identifies a security issue involving the affected technology, but does not yet support a more specific impact claim.
Recommended Action
No confirmed vendor remediation is available in the current evidence. Confirm whether the affected technology is present in your environment and review the affected configuration.
Exposure
Exposure unknown
Aug 23, 2023 03:00
Exposure reason: This incident does not currently match a technology in My Interests.
Exploitation status: UNKNOWN
Primary entities:
Timeline
-
Incident first seen
Aug 23, 2023 03:00BugSkan first recorded this incident.
-
langchain vulnerable to arbitrary code execution
Aug 23, 2023 03:00OSV.dev · Research
Sources
OSV.dev · Aug 23, 2023 03:00
An issue in langchain v.0.0.171 allows a remote attacker to execute arbitrary code via the via the a json file to the `load_prompt` parameter. This is related to `__subclasses__` or a template.
Open publisher sourceMy Interests Match
Create an account to see which incidents overlap with your interests.