Junglewise Threat Intelligence

CVE-2024-7774: Langchain path traversal in file operations

CVE-2024-7774 · Severity: low · CVSS 3 · Published 2024-10-29

Vendors: LangChain.

Executive brief

Langchain is a popular library for building applications with large language models. A path traversal vulnerability in its file handling code allows attackers to save, read, overwrite, and delete files anywhere on a system where the application runs, bypassing intended directory restrictions and potentially compromising sensitive data or application integrity.

Technical details

A path traversal vulnerability exists in the getFullPath method of langchain (npm package) versions prior to 0.2.19, exploitable through setFileContent, getParsedFile, and mdelete methods. The vulnerability stems from insufficient input sanitization when constructing file paths, allowing attackers to use path traversal sequences (e.g., ../) to escape the intended directory. The attack vector is network-based with no authentication or user interaction required (CVSS 3.0 AV:N/AC:L/PR:N/UI:N). An attacker can read text files, write files to arbitrary locations, overwrite existing files, and delete files on the affected system. A fix was released in version 0.2.19 (commit a0fad77).

Affected products

  • Langchain langchain before 0.2.19

Timeline

  • 2024-10-29: disclosed
  • 2024-10-29: patched: Fix released in version 0.2.19

References