langchain_experimental (aka LangChain Experimental) in LangChain prior to 0.0.306 allows an malicious user to bypass the CVE-2023-36258 fix and execute arbitrary code via __import__ in Python code, which is not prohibited by pal_chain/base.py.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
langchain langchain experimental 0.0.14 |