langchain vulnerable to arbitrary code execution
Critical severity
GitHub Reviewed
Published
Aug 22, 2023
to the GitHub Advisory Database
•
Updated Sep 30, 2024
Description
Published by the National Vulnerability Database
Aug 22, 2023
Published to the GitHub Advisory Database
Aug 22, 2023
Reviewed
Aug 23, 2023
Last updated
Sep 30, 2024
An issue in langchain v.0.0.171 allows a remote attacker to execute arbitrary code via the via the a json file to the
load_prompt
parameter. This is related to__subclasses__
or a template.References