CVE-2023-39631

GHSA-f73w-4m7g-ch9x CRITICAL
Published September 1, 2023

An issue in LanChain-ai Langchain v.0.0.245 allows a remote attacker to execute arbitrary code via the evaluate function in the numexpr...

Full analysis pending. Showing NVD description excerpt.

Affected Systems

Package Ecosystem Vulnerable Range Patched
langchain pip < 0.0.308 0.0.308
langchain pip No patch
numexpr pip < 2.8.5 2.8.5

Severity & Risk

CVSS 3.1
9.8 / 10
EPSS
3.3%
chance of exploitation in 30 days
KEV Status
Not in KEV
Sophistication
N/A

Recommended Action

Patch available

Update langchain to version 0.0.308

Update numexpr to version 2.8.5

Compliance Impact

Compliance analysis pending. Sign in for full compliance mapping when available.

Technical Details

NVD Description

An issue in LanChain-ai Langchain v.0.0.245 allows a remote attacker to execute arbitrary code via the evaluate function in the numexpr library.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Timeline

Published
September 1, 2023
Last Modified
February 20, 2025
First Seen
September 1, 2023