CRITICAL9.8
PYSEC-2023-163
Quick fix
PYSEC-2023-163 — numexpr: upgrade to the fixed version with the command below.
pip install --upgrade 'numexpr>=2.8.5'Details
An issue in LanChain-ai Langchain v.0.0.245 allows a remote attacker to execute arbitrary code via the evaluate function in the numexpr library.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/pydata/numexpr/issues/442[EVIDENCE]
- https://github.com/pydata/numexpr/issues/442[REPORT]
- https://github.com/pydata/numexpr/issues/442[FIX]
- https://github.com/langchain-ai/langchain/issues/8363[EVIDENCE]
- https://github.com/langchain-ai/langchain/issues/8363[REPORT]
- https://github.com/langchain-ai/langchain/issues/8363[FIX]
- https://github.com/advisories/GHSA-f73w-4m7g-ch9x[ADVISORY]