langchain_experimental (aka LangChain Experimental) before 0.0.61 for LangChain provides Python REPL access without an opt-in step. NOTE; this issue exists because of an incomplete fix for CVE-2024-27444.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| langchain-experimental(PyPI) | 0 | 0.0.61 | N/A |
CVSS Metrics