Junglewise Threat Intelligence

CVE-2023-39631: PYSEC-2023-162 - An issue in LanChain-ai Langchain v.0.0.245 allows a remote attacker to execute arbitrary code via the evaluate function in the numexpr libr

CVE-2023-39631 · Severity: low · CVSS 3.1 · Published 2023-09-01

Technologies: langchain (PyPI). Vendors: PyPI.

Executive brief

An issue in LanChain-ai Langchain v.0.0.245 allows a remote attacker to execute arbitrary code via the evaluate function in the numexpr library.

Affected products

  • PyPI langchain
  • PyPI numexpr

Related threats