Sploitus

CVE-2024-28088

1 known exploit for CVE-2024-28088

LangChain through 0.1.10 allows ../ directory traversal by an actor who is able to control the final part of the path parameter in a load_chain call. This bypasses the intended behavior of loading configurations only from the hwchase17/langchain-hub GitHub repository. The outcome can be disclosure of an API key for a large language model online service, or remote code execution. (A patch is available as of release 0.1.29 of langchain-core.)

Affected products
Langchain
Langchain
< 0.1.12
Fix
Available
CVSS 3.1
8.1 HIGH
EPSS
1.7% (76th percentile)
Weakness
CWE-31, CWE-22
NVD status
Analyzed
Published
2024-03-03
CVE-2024-28088 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2024-28088

Proof-of-concept code and exploit modules indexed by Sploitus