Junglewise Threat Intelligence

CVE-2023-39659: PYSEC-2023-147 - An issue in langchain langchain-ai v.0.0.232 and before allows a remote attacker to execute arbitrary code via a crafted script to the Pytho

CVE-2023-39659 · Severity: low · CVSS 3.1 · Published 2023-08-15

Technologies: langchain (PyPI). Vendors: PyPI.

Executive brief

An issue in langchain langchain-ai v.0.0.232 and before allows a remote attacker to execute arbitrary code via a crafted script to the PythonAstREPLTool._run component.

Affected products

  • PyPI langchain

Related threats