Executive brief
An issue in Harrison Chase langchain v.0.0.194 and before allows a remote attacker to execute arbitrary code via the from_math_prompt and from_colored_object_prompt functions.
Affected products
- PyPI langchain
Junglewise Threat Intelligence
CVE-2023-38896 · Severity: low · CVSS 3.1 · Published 2023-08-15
Technologies: langchain (PyPI). Vendors: PyPI.
An issue in Harrison Chase langchain v.0.0.194 and before allows a remote attacker to execute arbitrary code via the from_math_prompt and from_colored_object_prompt functions.