VDB
Sign up
CRITICAL9.8

PYSEC-2026-374

LangChain Experimental Eval Injection vulnerability

Details

langchain_experimental (aka LangChain Experimental) 0.1.17 through 0.3.0 for LangChain allows attackers to execute arbitrary code through sympy.sympify (which uses eval) in LLMSymbolicMathChain. LLMSymbolicMathChain was introduced in fcccde406dd9e9b05fc9babcbeb9ff527b0ec0c6 (2023-10-05).

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/langchain-experimental
Introduced in: 0.1.17

No fixed version published yet for langchain-experimental (pip). Pin to a known-safe version or switch to an alternative.

References