CVE-2023-36281
An issue in langchain v.0.0.171 allows a remote attacker to execute arbitrary code via a JSON file to load_prompt. This is related to __subclasses__ or a template.
- Affected products
- Langchain
- Langchain
- = 0.0.171
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 3.4% (88th percentile)
- Weakness
- CWE-94
- NVD status
- Modified
- Published
- 2023-08-22
CVE-2023-36281 at NVD
2 known exploits for CVE-2023-36281
Proof-of-concept code and exploit modules indexed by Sploitus