Логотип exploitDog
bind:CVE-2024-28088
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-28088

Количество 2

Количество 2

nvd логотип

CVE-2024-28088

почти 2 года назад

LangChain through 0.1.10 allows ../ directory traversal by an actor who is able to control the final part of the path parameter in a load_chain call. This bypasses the intended behavior of loading configurations only from the hwchase17/langchain-hub GitHub repository. The outcome can be disclosure of an API key for a large language model online service, or remote code execution. (A patch is available as of release 0.1.29 of langchain-core.)

CVSS3: 8.1
EPSS: Средний
github логотип

GHSA-h59x-p739-982c

почти 2 года назад

LangChain directory traversal vulnerability

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-28088

LangChain through 0.1.10 allows ../ directory traversal by an actor who is able to control the final part of the path parameter in a load_chain call. This bypasses the intended behavior of loading configurations only from the hwchase17/langchain-hub GitHub repository. The outcome can be disclosure of an API key for a large language model online service, or remote code execution. (A patch is available as of release 0.1.29 of langchain-core.)

CVSS3: 8.1
11%
Средний
почти 2 года назад
github логотип
GHSA-h59x-p739-982c

LangChain directory traversal vulnerability

11%
Средний
почти 2 года назад

Уязвимостей на страницу