9.8
CVSSv3

CVE-2023-44467

Published: 09/10/2023 Updated: 26/02/2024
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

langchain_experimental (aka LangChain Experimental) in LangChain prior to 0.0.306 allows an malicious user to bypass the CVE-2023-36258 fix and execute arbitrary code via __import__ in Python code, which is not prohibited by pal_chain/base.py.

Vulnerable Product Search on Vulmon Subscribe to Product

langchain langchain experimental 0.0.14