Количество 2
Количество 2
CVE-2024-5998
больше 1 года назад
A vulnerability in the FAISS.deserialize_from_bytes function of langchain-ai/langchain allows for pickle deserialization of untrusted data. This can lead to the execution of arbitrary commands via the os.system function. The issue affects the latest version of the product.
CVSS3: 7.8
EPSS: Низкий
GHSA-f2jm-rw3h-6phg
больше 1 года назад
LangChain pickle deserialization of untrusted data
CVSS3: 5.2
EPSS: Низкий
Уязвимостей на страницу
20
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2024-5998 A vulnerability in the FAISS.deserialize_from_bytes function of langchain-ai/langchain allows for pickle deserialization of untrusted data. This can lead to the execution of arbitrary commands via the os.system function. The issue affects the latest version of the product. | CVSS3: 7.8 | 0% Низкий | больше 1 года назад | |
GHSA-f2jm-rw3h-6phg LangChain pickle deserialization of untrusted data | CVSS3: 5.2 | 0% Низкий | больше 1 года назад |
Уязвимостей на страницу
20