langchain-experimental
5 advisories in the AI Sec Watch database name langchain-experimental (PyPI). langchain-experimental (PyPI) has declared an LLM component as a dependency since 2023-07-21. The most recent advisory that names langchain-experimental and states a fix gives 0.0.21.
Building applications with LLMs through composability
The first release to declare it was version 0.0.1rc1.
Advisories
Advisories that name langchain-experimental as affected and state PyPI as its ecosystem. For a version-exact check of your own dependencies, use Stack Check.
| Advisory | Severity | Affected | Fixed in | Published |
|---|---|---|---|---|
| CVE-2024-46946LangChain Experimental arbitrary code execution through LLMSymbolicMathChain | Critical | >= 0.1.17, <= 0.3.0 | 2024-09-19 | |
| CVE-2024-21513langchain-experimental arbitrary code execution when retrieving database values | High | >= 0, < 0.0.21 | 0.0.21 | 2024-07-15 |
| CVE-2024-38459langchain_experimental Python REPL access without opt-in step | High | < 0.0.61 | 0.0.61 | 2024-06-16 |
| CVE-2024-27444langchain_experimental code execution via Python attribute bypass in pal_chain | Critical | < 0.0.52 | 0.0.52 | 2024-02-26 |
| CVE-2023-44467LangChain Experimental sandbox bypass allows arbitrary code execution | Critical | <= 0.0.14 | 2023-10-10 |
Dependencies of the latest release
As declared in PyPI metadata for version 0.4.2. Optional extras are listed with their extra name.
- langchain-communityLangChain
- langchain-coreLangChain
Tracked packages that depend on it
Among the packages in the registry; not every dependent on PyPI.