VDB
Sign up
CRITICAL9.8

PYSEC-2026-375

LangChain Experimental vulnerable to arbitrary code execution

Quick fix

PYSEC-2026-375 — langchain-experimental: upgrade to the fixed version with the command below.

pip install --upgrade 'langchain-experimental>=0.0.52'

Details

langchain_experimental (aka LangChain Experimental) before 0.0.52, part of LangChain before 0.1.8, allows an attacker to bypass the CVE-2023-44467 fix and execute arbitrary code via the `__import__`, `__subclasses__`, `__builtins__`, `__globals__`, `__getattribute__`, `__bases__`, `__mro__`, or `__base__` attribute in Python code. These are not prohibited by `pal_chain/base.py`.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/langchain-experimental
Introduced in: 0Fixed in: 0.0.52
Fixpip install --upgrade 'langchain-experimental>=0.0.52'

References