Loading HuntDB...

GHSA-v8vj-cv27-hjv8

GitHub Security Advisory

LangChain Experimental vulnerable to arbitrary code execution

✓ GitHub Reviewed CRITICAL Has CVE

Advisory Details

langchain_experimental (aka LangChain Experimental) before 0.0.52, part of LangChain before 0.1.8, allows an attacker to bypass the CVE-2023-44467 fix and execute arbitrary code via the `__import__`, `__subclasses__`, `__builtins__`, `__globals__`, `__getattribute__`, `__bases__`, `__mro__`, or `__base__` attribute in Python code. These are not prohibited by `pal_chain/base.py`.

Affected Packages

PyPI langchain-experimental
Affected versions: 0 (fixed in 0.0.52)

Related CVEs

Key Information

GHSA ID
GHSA-v8vj-cv27-hjv8
Published
February 26, 2024 6:30 PM
Last Modified
August 6, 2024 6:35 PM
CVSS Score
9.0 /10
Primary Ecosystem
PyPI
Primary Package
langchain-experimental
GitHub Reviewed
✓ Yes

Dataset

Last updated: June 16, 2025 6:25 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.