漏洞与安全社区 / 第三方国际
CVE-2024-3571: langchain vulnerable to path traversal
今日摘要使用自己的 API,仅供个人查看
来源摘要
langchain-ai/langchain is vulnerable to path traversal due to improper limitation of a pathname to a restricted directory ('Path Traversal') in its LocalFileStore functionality. An attacker can leverage this vulnerability to read or write files anywhere on the filesystem, potentially leading to information disclosure or remote code execution. The issue lies in the handling of file paths in the mset and mget methods, where user-supplied input is not adequately sanitized, allowing directory traversal sequences to reach unintended directories.
阅读原始来源- 来源
- LangChain 安全公告 · 社区 / 第三方
- 来源发布
- 2024/04/16 08:30
- 来源更新
- 2024/04/17 02:26
- 首次采集
- 2026/09/19 13:00
本文为公开信息索引与摘要,详情及后续变化请以原始来源为准。