logo

Database

Lack of data validation In langchain

Description

LangChain vulnerable to arbitrary code execution An issue in langchain langchain-ai before version 0.0.325 allows a remote attacker to execute arbitrary code via a crafted script to the PythonAstREPLTool._run component.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions
FLAT-4B23E – Vulnerability | Fluid Attacks Database