VDB
Sign up
CRITICAL9.8

PYSEC-2023-194

Quick fix

PYSEC-2023-194 — langchain-experimental: upgrade to the fixed version with the command below.

pip install --upgrade 'langchain-experimental>=4c97a10bd0d9385cfee234a63b5bd826a295e483'

Details

langchain_experimental 0.0.14 allows an attacker to bypass the CVE-2023-36258 fix and execute arbitrary code via the PALChain in the python exec method.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/langchain-experimental
Introduced in: 0Fixed in: 4c97a10bd0d9385cfee234a63b5bd826a295e483
Fixpip install --upgrade 'langchain-experimental>=4c97a10bd0d9385cfee234a63b5bd826a295e483'

References