CVE-2023-36188Critical· 9.8▾ Midnightlangchain vulnerable to arbitrary code execution
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.4 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.9%
1.9% → 1.9%
An issue in langchain allows a remote attacker to execute arbitrary code via the PALChain parameter in the Python exec method.
langchain < 0.0.247Upgrade to a patched release:
langchain 0.0.247Connected by shared product, vendor, weakness, or advisory.
CVE-2024-3571Medium· 6.5langchain vulnerable to path traversal
CVE-2024-0243Low· 3.7langchain Server-Side Request Forgery vulnerability
CVE-2026-55443Medium· 5.1LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders
CVE-2023-32786High· 7.5Langchain Server-Side Request Forgery vulnerability
CVE-2026-34070High· 7.5LangChain is a framework for building agents and LLM-powered applications
GHSA-gr75-jv2w-4656Medium· 5.1LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders