Loading HuntDB...

GHSA-wmvm-9vqv-5qpp

GitHub Security Advisory

langchain_experimental Code Execution via Python REPL access

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

langchain_experimental (aka LangChain Experimental) before 0.0.61 for LangChain provides Python REPL access without an opt-in step. NOTE; this issue exists because of an incomplete fix for CVE-2024-27444.

Affected Packages

PyPI langchain-experimental
Affected versions: 0 (fixed in 0.0.61)

Related CVEs

Key Information

GHSA ID
GHSA-wmvm-9vqv-5qpp
Published
June 16, 2024 3:30 PM
Last Modified
July 5, 2024 9:18 PM
CVSS Score
7.5 /10
Primary Ecosystem
PyPI
Primary Package
langchain-experimental
GitHub Reviewed
✓ Yes

Dataset

Last updated: June 16, 2025 6:25 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.