Lucene search

K
cveMitreCVE-2023-44467
HistoryOct 09, 2023 - 8:15 p.m.

CVE-2023-44467

2023-10-0920:15:10
mitre
web.nvd.nist.gov
128
cve-2023-44467
langchain_experimental
code execution
palchain
python
nvd

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.5

Confidence

High

EPSS

0.003

Percentile

71.7%

langchain_experimental (aka LangChain Experimental) in LangChain before 0.0.306 allows an attacker to bypass the CVE-2023-36258 fix and execute arbitrary code via import in Python code, which is not prohibited by pal_chain/base.py.

Affected configurations

Nvd
Node
langchainlangchain_experimentalMatch0.0.14python
VendorProductVersionCPE
langchainlangchain_experimental0.0.14cpe:2.3:a:langchain:langchain_experimental:0.0.14:*:*:*:*:python:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.5

Confidence

High

EPSS

0.003

Percentile

71.7%