Executive brief
langchain_experimental 0.0.14 allows an attacker to bypass the CVE-2023-36258 fix and execute arbitrary code via the PALChain in the python exec method.
Affected products
- PyPI langchain-experimental
Junglewise Threat Intelligence
CVE-2023-44467 · Severity: low · CVSS 3.1 · Published 2023-10-09
Technologies: langchain-experimental (PyPI). Vendors: PyPI.
langchain_experimental 0.0.14 allows an attacker to bypass the CVE-2023-36258 fix and execute arbitrary code via the PALChain in the python exec method.