{"data":{"ecosystem":"pypi","name":"langchain-experimental","url":"https://aisecwatch.com/packages/pypi/langchain-experimental","latestVersion":"0.4.2","firstReleaseAt":"2023-07-21T21:44:36.666Z","repository":"https://github.com/langchain-ai/langchain-experimental/tree/main/libs/experimental","llm":{"exposure":"direct","depth":0,"integratedAt":"2023-07-21T21:44:36.666Z","integratedVersion":"0.0.1rc1","sdks":["langchain"],"path":[]},"authority":{"profile":[],"fromDependencies":[]},"dependencies":[{"ecosystem":"pypi","name":"langchain-community","versionSpec":"<1.0.0,>=0.4.2","scope":"runtime"},{"ecosystem":"pypi","name":"langchain-core","versionSpec":"<2.0.0,>=1.4.0","scope":"runtime"}],"advisories":[{"id":"cfc91b7a-e2ad-4bbb-b0cf-3e892ec2be36","url":"https://aisecwatch.com/issues/cfc91b7a-e2ad-4bbb-b0cf-3e892ec2be36","cveId":"CVE-2024-46946","title":"CVE-2024-46946: langchain_experimental (aka LangChain Experimental) 0.1.17 through 0.3.0 for LangChain allows attackers to execute…","headline":"LangChain Experimental arbitrary code execution through LLMSymbolicMathChain","severity":"critical","publishedAt":"2024-09-19T09:15:11.857Z","affected":["langchain-experimental@>= 0.1.17, <= 0.3.0"],"epssScore":0.01387,"matchedBy":"ecosystem"},{"id":"3ffc9fd5-1aea-4bc8-9073-cd843137eb5f","url":"https://aisecwatch.com/issues/3ffc9fd5-1aea-4bc8-9073-cd843137eb5f","cveId":"CVE-2024-21513","title":"CVE-2024-21513: Versions of the package langchain-experimental from 0.0.15 and before 0.0.21 are vulnerable to Arbitrary Code Execution…","headline":"langchain-experimental arbitrary code execution when retrieving database values","severity":"high","publishedAt":"2024-07-15T09:15:01.857Z","affected":["langchain-experimental@>= 0, < 0.0.21 (fixed: 0.0.21)"],"epssScore":0.01893,"matchedBy":"ecosystem"},{"id":"da53774d-698f-4479-ad8b-7744f5da7d55","url":"https://aisecwatch.com/issues/da53774d-698f-4479-ad8b-7744f5da7d55","cveId":"CVE-2024-38459","title":"CVE-2024-38459: langchain_experimental (aka LangChain Experimental) before 0.0.61 for LangChain provides Python REPL access without an…","headline":"langchain_experimental Python REPL access without opt-in step","severity":"high","publishedAt":"2024-06-16T19:15:51.840Z","affected":["langchain-experimental@< 0.0.61 (fixed: 0.0.61)"],"epssScore":0.00227,"matchedBy":"ecosystem"},{"id":"00948158-5f84-41c9-98b3-7fe340a504ec","url":"https://aisecwatch.com/issues/00948158-5f84-41c9-98b3-7fe340a504ec","cveId":"CVE-2024-27444","title":"CVE-2024-27444: langchain_experimental (aka LangChain Experimental) in LangChain before 0.1.8 allows an attacker to bypass the…","headline":"langchain_experimental code execution via Python attribute bypass in pal_chain","severity":"critical","publishedAt":"2024-02-26T21:28:00.430Z","affected":["langchain-experimental@< 0.0.52 (fixed: 0.0.52)"],"epssScore":0.00773,"matchedBy":"ecosystem"},{"id":"4a16d742-d84c-4ecc-9d6a-dbae7381c311","url":"https://aisecwatch.com/issues/4a16d742-d84c-4ecc-9d6a-dbae7381c311","cveId":"CVE-2023-44467","title":"CVE-2023-44467: langchain_experimental (aka LangChain Experimental) in LangChain before 0.0.306 allows an attacker to bypass the…","headline":"LangChain Experimental sandbox bypass allows arbitrary code execution","severity":"critical","publishedAt":"2023-10-10T00:15:10.480Z","affected":["langchain-experimental@<= 0.0.14"],"epssScore":0.00951,"matchedBy":"ecosystem"}],"checkedAt":"2026-10-09T21:51:07.605Z"},"meta":{"advisoryMatching":"by package name and ecosystem; an advisory with no ecosystem recorded for the package is matched by name alone"}}