- CVSS
- CRITICAL · 9.8v3.1CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Published
- 2023-09-01
- Weakness
- CWE-94
- Source
- nvd.nist.gov/vuln/detail/CVE-2023-39631
Description
An issue in LanChain-ai Langchain v.0.0.245 allows a remote attacker to execute arbitrary code via the evaluate function in the numexpr library.
References
How GTK Cyber trains on this
AI security training at GTK Cyber covers the LLM and ML-pipeline vulnerability classes that vulnerabilities like CVE-2023-39631 fall into. Our hands-on courses are taught by Charles Givre and other practitioners who break and defend production AI systems.