CVE-2023-29374
critical · 9.8In LangChain through 0.0.131, the LLMMathChain chain allows prompt injection attacks that can execute arbitrary code via the Python exec method.
9.8
CVSS
39.7%
EPSS (exploit prob.)
99th
EPSS percentile
2023-04-05
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-74
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| langchain | langchain | <= 0.0.131 |
Check a specific version with /api/v1/cve/match.
References
- https://github.com/hwchase17/langchain/issues/1026
- https://github.com/hwchase17/langchain/issues/814
- https://github.com/hwchase17/langchain/pull/1119
- https://twitter.com/rharang/status/1641899743608463365/photo/1
- https://github.com/hwchase17/langchain/issues/1026
- https://github.com/hwchase17/langchain/issues/814
- https://github.com/hwchase17/langchain/pull/1119
- https://twitter.com/rharang/status/1641899743608463365/photo/1
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2023-29374