Junglewise Threat Intelligence

CVE-2023-36095: PYSEC-2023-138 - An issue in Harrison Chase langchain v.0.0.194 allows an attacker to execute arbitrary code via the python exec calls in the PALChain, affec

CVE-2023-36095 · Severity: low · CVSS 3.1 · Published 2023-08-05

Technologies: langchain (PyPI). Vendors: PyPI.

Executive brief

An issue in Harrison Chase langchain v.0.0.194 allows an attacker to execute arbitrary code via the python exec calls in the PALChain, affected functions include from_math_prompt and from_colored_object_prompt.

Affected products

  • PyPI langchain

Related threats