Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-p2qj-r53j-h3xj | LangChain Experimental Eval Injection vulnerability |
Wed, 16 Jul 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Langchain langchain-experimental
|
|
| CPEs | cpe:2.3:a:langchain:langchain-experimental:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Langchain langchain-experimental
|
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 19 Sep 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Langchain
Langchain langchain Experimental |
|
| Weaknesses | CWE-20 | |
| CPEs | cpe:2.3:a:langchain:langchain_experimental:*:*:*:*:*:python:*:* | |
| Vendors & Products |
Langchain
Langchain langchain Experimental |
|
| Metrics |
cvssV3_1
|
Thu, 19 Sep 2024 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | langchain_experimental (aka LangChain Experimental) 0.1.17 through 0.3.0 for LangChain allows attackers to execute arbitrary code through sympy.sympify (which uses eval) in LLMSymbolicMathChain. LLMSymbolicMathChain was introduced in fcccde406dd9e9b05fc9babcbeb9ff527b0ec0c6 (2023-10-05). | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-19T14:06:52.692Z
Reserved: 2024-09-15T00:00:00.000Z
Link: CVE-2024-46946
Updated: 2024-09-19T14:06:19.168Z
Status : Analyzed
Published: 2024-09-19T05:15:11.857
Modified: 2025-07-16T13:49:54.500
Link: CVE-2024-46946
No data.
OpenCVE Enrichment
No data.
Github GHSA