漏洞与安全社区 / 第三方国际
CVE-2024-28088: LangChain directory traversal vulnerability
今日摘要使用自己的 API,仅供个人查看
来源摘要
LangChain through 0.1.10 allows ../ directory traversal by an actor who is able to control the final part of the path parameter in a load_chain call. This bypasses the intended behavior of loading configurations only from the hwchase17/langchain-hub GitHub repository. The outcome can be disclosure of an API key for a large language model online service, or remote code execution.
阅读原始来源- 来源
- LangChain 安全公告 · 社区 / 第三方
- 来源发布
- 2024/03/04 08:30
- 来源更新
- 2024/03/15 07:14
- 首次采集
- 2026/09/19 13:00
本文为公开信息索引与摘要,详情及后续变化请以原始来源为准。