A vulnerability in the FAISS.deserialize_from_bytes function of langchain-ai/langchain allows for pickle deserialization of untrusted data. This can lead to the execution of arbitrary commands via the os.system function. The issue affects the latest version of the product.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| langchain-community(PyPI) | 0 | 0.2.4 | N/A |
CVSS Metrics