CVE-2023-36258

CRITICAL

LangChain < 0.0.236 - Remote Code Execution via Python Code Injection

Title source: llm
STIX 2.1

Description

An issue in LangChain before 0.0.236 allows an attacker to execute arbitrary code because Python code with os.system, exec, or eval can be used.

References (1)

Core 1
Core References
Exploit, Issue Tracking, Mitigation
https://github.com/hwchase17/langchain/issues/5872

Scores

CVSS v3 9.8
EPSS 0.0098
EPSS Percentile 57.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-94
Status published
Products (2)
langchain/langchain 0.0.199
pypi/langchain 0 - 0.0.247PyPI
Published Jul 03, 2023
Tracked Since Feb 18, 2026