Executive brief
In LangChain through 0.0.131, the LLMMathChain chain allows prompt injection attacks that can execute arbitrary code via the Python exec method.
Affected products
- PyPI langchain
Junglewise Threat Intelligence
CVE-2023-29374 · Severity: low · CVSS 3.1 · Published 2023-04-05
Technologies: langchain (PyPI). Vendors: PyPI.
In LangChain through 0.0.131, the LLMMathChain chain allows prompt injection attacks that can execute arbitrary code via the Python exec method.