CVE-2024-27444
Dashboard / Vulnerabilities / CVE-2024-27444
CVE-2024-27444
Published: 26 Feb 2024Last Modified: 12 Aug 2026
Aliases:
Summary:
Details: langchain_experimental (aka LangChain Experimental) in LangChain before 0.1.8 allows an attacker to bypass the CVE-2023-44467 fix and execute arbitrary code via the __import__, __subclasses__, __builtins__, __globals__, __getattribute__, __bases__, __mro__, or __base__ attribute in Python code. These are not prohibited by pal_chain/base.py.
References: https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/27xxx/CVE-2024-27444.json, https://nvd.nist.gov/vuln/detail/CVE-2024-27444, https://github.com/langchain-ai/langchain/commit/de9a6cdf163ed00adaf2e559203ed0a9ca2f1de7
Affected packages
Package
Name:
Purl:
Affected ranges
Affected versions
v0.1.7
v0.1.6
v0.1.5
v0.1.4
v0.1.3
v0.1.2
v0.1.1
v0.1.0
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
