Database/AI/ML frameworks & serving
langchain-experimental: Arbitrary code execution in 0.1.17–0.3.0
CVSS 9.8CVE-2024-46946AI/ML frameworks & servingcurated
Impact
Arbitrary code execution in 0.1.17–0.3.0
Who can reach it
Untrusted prompt input
What to do
Upgrade
References
Related entries
- langchain-experimental: Second bypass of CVE-2023-44467CVE-2024-27444 · langchain-experimentalCritical
- Gradio: SSRF from the file-upload/proxy pathCVE-2024-47167 · GradioCritical
- PyTorch (`torch.distributed` RemoteModule / RPC): Deserialization RCE across the distributed RPC channelCVE-2024-48063 · PyTorch (`torch.distributed` RemoteModule / RPC)Critical
- PyTorch Lightning: RCE via deserialization of untrusted checkpointCVE-2024-5452 · PyTorch LightningCritical
- vLLM (`AsyncEngineRPCServer`): Unsafe deserialization on RPC entrypointsCVE-2024-9053 · vLLM (`AsyncEngineRPCServer`)Critical
- BentoML (runner server): Deserialization RCE on the internal runner serverCVE-2024-9070 · BentoML (runner server)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.