{"data":{"ecosystem":"pypi","name":"numexpr","url":"https://aisecwatch.com/packages/pypi/numexpr","latestVersion":"2.14.2","firstReleaseAt":"2009-01-23T12:57:00.000Z","repository":"https://github.com/pydata/numexpr","llm":{"exposure":"none","depth":null,"integratedAt":null,"integratedVersion":null,"sdks":[],"path":[]},"authority":{"profile":[],"fromDependencies":[]},"dependencies":[{"ecosystem":"pypi","name":"numpy","versionSpec":">=1.26.0","scope":"runtime"}],"advisories":[{"id":"a59d48d1-82c7-45b4-91a5-6813bdefea2a","url":"https://aisecwatch.com/issues/a59d48d1-82c7-45b4-91a5-6813bdefea2a","cveId":"CVE-2023-39631","title":"CVE-2023-39631: An issue in LanChain-ai Langchain v.0.0.245 allows a remote attacker to execute arbitrary code via the evaluate…","headline":"LanChain-ai Langchain code execution through evaluate function","severity":"critical","publishedAt":"2023-09-01T20:15:08.370Z","affected":["langchain@< 0.0.308 (fixed: 0.0.308)","numexpr@< 2.8.5 (fixed: 2.8.5)"],"epssScore":0.016}],"checkedAt":"2026-10-09T22:13:14.013Z"},"meta":{"advisoryMatching":"by package name; advisory records do not state an ecosystem"}}