Filtered by vendor Langchain
Subscribe
Total
49 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-38860 | 1 Langchain | 1 Langchain | 2026-06-17 | N/A | 9.8 CRITICAL |
| An issue in LangChain v.0.0.231 allows a remote attacker to execute arbitrary code via the prompt parameter. | |||||
| CVE-2023-36281 | 1 Langchain | 1 Langchain | 2026-06-17 | N/A | 9.8 CRITICAL |
| An issue in langchain v.0.0.171 allows a remote attacker to execute arbitrary code via a JSON file to load_prompt. This is related to __subclasses__ or a template. | |||||
| CVE-2023-36258 | 1 Langchain | 1 Langchain | 2026-06-17 | N/A | 9.8 CRITICAL |
| An issue in LangChain before 0.0.236 allows an attacker to execute arbitrary code because Python code with os.system, exec, or eval can be used. | |||||
| CVE-2023-36189 | 1 Langchain | 1 Langchain | 2026-06-17 | N/A | 7.5 HIGH |
| SQL injection vulnerability in langchain before v0.0.247 allows a remote attacker to obtain sensitive information via the SQLDatabaseChain component. | |||||
| CVE-2023-36188 | 1 Langchain | 1 Langchain | 2026-06-17 | N/A | 9.8 CRITICAL |
| An issue in langchain v.0.0.64 allows a remote attacker to execute arbitrary code via the PALChain parameter in the Python exec method. | |||||
| CVE-2023-34541 | 1 Langchain | 1 Langchain | 2026-06-17 | N/A | 9.8 CRITICAL |
| Langchain 0.0.171 is vulnerable to Arbitrary code execution in load_prompt. | |||||
| CVE-2023-34540 | 1 Langchain | 1 Langchain | 2026-06-17 | N/A | 9.8 CRITICAL |
| Langchain before v0.0.225 was discovered to contain a remote code execution (RCE) vulnerability in the component JiraAPIWrapper (aka the JIRA API wrapper). This vulnerability allows attackers to execute arbitrary code via crafted input. As noted in the "releases/tag" reference, a fix is available. | |||||
| CVE-2023-32786 | 1 Langchain | 1 Langchain | 2026-06-17 | N/A | 7.5 HIGH |
| In Langchain through 0.0.155, prompt injection allows an attacker to force the service to retrieve data from an arbitrary URL, essentially providing SSRF and potentially injecting content into downstream tasks. | |||||
| CVE-2023-29374 | 1 Langchain | 1 Langchain | 2026-06-17 | N/A | 9.8 CRITICAL |
| In LangChain through 0.0.131, the LLMMathChain chain allows prompt injection attacks that can execute arbitrary code via the Python exec method. | |||||
