CVE-2023-29374

CRITICAL

LangChain <0.0.131 - Code Injection

Title source: llm
STIX 2.1

Description

In LangChain through 0.0.131, the LLMMathChain chain allows prompt injection attacks that can execute arbitrary code via the Python exec method.

Scores

CVSS v3 9.8
EPSS 0.3965
EPSS Percentile 98.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-74
Status published
Products (2)
langchain/langchain < 0.0.131
pypi/langchain 0PyPI
Published Apr 05, 2023
Tracked Since Feb 18, 2026