Server side template injection In langchain
Description
Langchain vulnerable to arbitrary code execution via the evaluate function in the numexpr library An issue in LanChain-ai Langchain v.0.0.245 allows a remote attacker to execute arbitrary code via the evaluate function in the numexpr library.
Patches: Released in v.0.0.308. numexpr dependency is optional for langchain.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Aliases
1. 2. 3. 4.
References
1. 2. 3. 4. 5. 6. 7.