Vulnerability index

Browse CVEs

45 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Langchain HIGH 7.5
CVE-2023-32786

In Langchain through 0.0.155, prompt injection allows an attacker to force the service to retrieve data from an arbitrary URL, essentially providing …

Fix: after 0.0.155
Fix from $1,950 2023-10-20
Langchain HIGH 8.8
CVE-2023-46229EPSS 45%

LangChain before 0.0.317 allows SSRF via document_loaders/recursive_url_loader.py because crawling can proceed from an external server to an internal…

Fix: 0.0.317+
Fix from $1,950 2023-10-19
Langchain Experimental CRITICAL 9.8
CVE-2023-44467

langchain_experimental (aka LangChain Experimental) in LangChain before 0.0.306 allows an attacker to bypass the CVE-2023-36258 fix and execute arbit…

Patch available
Fix from $2,300 2023-10-09
Langchain CRITICAL 9.8
CVE-2023-39631

An issue in LanChain-ai Langchain v.0.0.245 allows a remote attacker to execute arbitrary code via the evaluate function in the numexpr library.

Patch available
Fix from $2,300 2023-09-01
Langchain CRITICAL 9.8
CVE-2023-36281

An issue in langchain v.0.0.171 allows a remote attacker to execute arbitrary code via a JSON file to load_prompt. This is related to __subclasses__ …

No fix yet
Fix from $2,300 2023-08-22
Langchain CRITICAL 9.8
CVE-2023-38896

An issue in Harrison Chase langchain v.0.0.194 and before allows a remote attacker to execute arbitrary code via the from_math_prompt and from_colore…

Fix: after 0.0.194
Fix from $2,300 2023-08-15
Langchain CRITICAL 9.8
CVE-2023-39659

An issue in langchain langchain-ai v.0.0.232 and before allows a remote attacker to execute arbitrary code via a crafted script to the PythonAstREPLT…

Fix: after 0.0.232
Fix from $2,300 2023-08-15
Langchain CRITICAL 9.8
CVE-2023-38860

An issue in LangChain v.0.0.231 allows a remote attacker to execute arbitrary code via the prompt parameter.

No fix yet
Fix from $2,300 2023-08-15
Langchain CRITICAL 9.8
CVE-2023-36095

An issue in Harrison Chase langchain v.0.0.194 allows an attacker to execute arbitrary code via the python exec calls in the PALChain, affected funct…

Mitigation only
Fix from $2,300 2023-08-05
Langchain CRITICAL 9.8
CVE-2023-36188

An issue in langchain v.0.0.64 allows a remote attacker to execute arbitrary code via the PALChain parameter in the Python exec method.

Patch available
Fix from $2,300 2023-07-06
Langchain HIGH 7.5
CVE-2023-36189

SQL injection vulnerability in langchain before v0.0.247 allows a remote attacker to obtain sensitive information via the SQLDatabaseChain component.

Patch available
Fix from $1,950 2023-07-06
Langchain CRITICAL 9.8
CVE-2023-36258

An issue in LangChain before 0.0.236 allows an attacker to execute arbitrary code because Python code with os.system, exec, or eval can be used.

No fix yet
Fix from $2,300 2023-07-03
Langchain CRITICAL 9.8
CVE-2023-34541

Langchain 0.0.171 is vulnerable to Arbitrary code execution in load_prompt.

No fix yet
Fix from $2,300 2023-06-20
Langchain CRITICAL 9.8
CVE-2023-34540

Langchain before v0.0.225 was discovered to contain a remote code execution (RCE) vulnerability in the component JiraAPIWrapper (aka the JIRA API wra…

Patch available
Fix from $2,300 2023-06-14
Langchain CRITICAL 9.8
CVE-2023-29374EPSS 40%

In LangChain through 0.0.131, the LLMMathChain chain allows prompt injection attacks that can execute arbitrary code via the Python exec method.

Fix: after 0.0.131
Fix from $2,300 2023-04-05