Security Advisory

CVE-2024-5998

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2024-09-17 11:50:13
Last updated 2024-09-17 13:34:15
Assigner @huntr_ai
CVSS score 5.2
State PUBLISHED

Description

A vulnerability in the FAISS.deserialize_from_bytes function of langchain-ai/langchain allows for pickle deserialization of untrusted data. This can lead to the execution of arbitrary commands via the os.system function. The issue affects the latest version of the product.