Last seen March 4, 2024

LangChain Remote Code Execution Vulnerability

LangChain through 0.1.10 allows ../ directory traversal by an actor who is able to control the final part of the path parameter in a load_chain call. This bypasses the intended behavior of loading configurations only from the hwchase17/langchain-hub GitHub repository. The outcome can be disclosure of an API key for a large language model online service, or remote code execution.

Technical Severity
Medium severity
Lifecycle Status

STABLE

What Happened

LangChain through 0.1.10 allows ../ directory traversal by an actor who is able to control the final part of the path parameter in a load_chain call. This bypasses the intended behavior of loading configurations only from the hwchase17/langchain-hub GitHub repository. The outcome can be disclosure of an API key for a large language model online service, or remote code execution.

Why This Matters

The evidence matters to defenders using LangChain because it could let an attacker run code in affected environments.

Recommended Action

Confirm whether GitHub is present in your environment and review vendor guidance for this report. Apply available patches or mitigations if your deployment matches the described conditions.

Exposure

My Interests Exposure

Exposure unknown

Recommended Response
Last Seen

Mar 04, 2024 06:00

Exposure reason: This incident does not currently match a technology in My Interests.

Exploitation status: UNKNOWN

Primary entities:

GitHubLangChainlangchain-coreRemote Code Executionvulnerabilitylangchain-ai/langchain

Timeline

  • Incident first seen
    Mar 04, 2024 06:00

    BugSkan first recorded this incident.

  • LangChain directory traversal vulnerability
    Mar 04, 2024 06:00

    GitHub Advisory Database · Vulnerability

Sources

LangChain directory traversal vulnerability

GitHub Advisory Database · Mar 04, 2024 06:00

LangChain through 0.1.10 allows ../ directory traversal by an actor who is able to control the final part of the path parameter in a load_chain call. This bypasses the intended behavior of loading configurations only from the hwchase17/langchain-hub GitHub repository. The outcome can be disclosure of an API key for a large language model online service, or remote code execution.

Open publisher source

Other BugSkan incidents that share identifiers, products, or vendors with this report.

My Interests Match

Want personalized relevance?

Create an account to see which incidents overlap with your interests.

← Back to incident intelligence