Database/AI/ML frameworks & serving
langchain-experimental: Second bypass of CVE-2023-44467
CVSS 9.8CVE-2024-27444AI/ML frameworks & servingcurated
Impact
Second bypass of CVE-2023-44467
Who can reach it
Untrusted prompt input
What to do
Upgrade past 0.1.8. Three CVEs for one sandbox — code-generating chains have no safe configuration
References
Related entries
- langchain-experimental: Arbitrary code execution in 0.1.17–0.3.0CVE-2024-46946 · langchain-experimentalCritical
- Pure Storage FlashArray Purity API endpoint: A specific call to a FlashArray endpoint escalates the caller's privilegesCVE-2024-3057 · Pure Storage FlashArray Purity API endpointCritical
- TorchServe: `allowed_urls` bypassCVE-2024-35198 · TorchServeCritical
- Keras / TensorFlow: Arbitrary code injection in Keras < 2.13 via Lambda-layer model loadingCVE-2024-3660 · Keras / TensorFlowCritical
- Gradio: Code injection via `gradio/component_meta.py`CVE-2024-39236 · GradioCritical
- Gradio: SSRF from the file-upload/proxy pathCVE-2024-47167 · GradioCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.