A vulnerability in the FAISS.deserialize_from_bytes function of langchain-ai/langchain allows for pickle deserialization of untrusted data. This can lead to the execution of arbitrary commands via the os.system function. The issue affects the latest version of the product.
References
Configurations
No configuration.
History
20 Sep 2024, 12:31
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
17 Sep 2024, 12:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-09-17 12:15
Updated : 2024-09-20 12:31
NVD link : CVE-2024-5998
Mitre link : CVE-2024-5998
CVE.ORG link : CVE-2024-5998
JSON object : View
Products Affected
No product.
CWE
CWE-502
Deserialization of Untrusted Data