VDB
Sign up
—

PYSEC-2024-7

Quick fix

PYSEC-2024-7 — embedchain: upgrade to the fixed version with the command below.

pip install --upgrade 'embedchain>=0.1.57'

Details

The OpenAPI loader in Embedchain before 0.1.57 allows attackers to execute arbitrary code, related to the openapi.py yaml.load function argument.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/embedchain
Introduced in: 0Fixed in: 0.1.57
Fixpip install --upgrade 'embedchain>=0.1.57'

References