CRITICAL9.8
PYSEC-2023-162
Quick fix
PYSEC-2023-162 — langchain: upgrade to the fixed version with the command below.
pip install --upgrade 'langchain>=0.0.308'Details
An issue in LanChain-ai Langchain v.0.0.245 allows a remote attacker to execute arbitrary code via the evaluate function in the numexpr library.
Are you affected?
Enter the version of the package you're using.