CRITICAL9.8
PYSEC-2023-194
Quick fix
PYSEC-2023-194 — langchain-experimental: upgrade to the fixed version with the command below.
pip install --upgrade 'langchain-experimental>=4c97a10bd0d9385cfee234a63b5bd826a295e483'Details
langchain_experimental 0.0.14 allows an attacker to bypass the CVE-2023-36258 fix and execute arbitrary code via the PALChain in the python exec method.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/langchain-experimental
Introduced in:
0Fixed in: 4c97a10bd0d9385cfee234a63b5bd826a295e483Fix
pip install --upgrade 'langchain-experimental>=4c97a10bd0d9385cfee234a63b5bd826a295e483'