A vulnerability in the FAISS.deserialize_from_bytes function of langchain-ai/langchain allows for pickle deserialization of untrusted data. This can lead to the execution of arbitrary commands via the os.system function. The issue affects the latest version of the product.
Metrics
Affected Vendors & Products
References
History
Wed, 30 Jul 2025 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Mon, 14 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Tue, 17 Sep 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Langchain
Langchain langchain |
|
CPEs | cpe:2.3:a:langchain:langchain:*:*:*:*:*:*:*:* | |
Vendors & Products |
Langchain
Langchain langchain |
|
Metrics |
ssvc
|
Tue, 17 Sep 2024 12:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability in the FAISS.deserialize_from_bytes function of langchain-ai/langchain allows for pickle deserialization of untrusted data. This can lead to the execution of arbitrary commands via the os.system function. The issue affects the latest version of the product. | |
Title | Deserialization of Untrusted Data in langchain-ai/langchain | |
Weaknesses | CWE-502 | |
References |
| |
Metrics |
cvssV3_0
|

Status: PUBLISHED
Assigner: @huntr_ai
Published: 2024-09-17T11:50:13.813Z
Updated: 2024-09-17T13:34:15.648Z
Reserved: 2024-06-14T13:32:32.118Z
Link: CVE-2024-5998

Updated: 2024-09-17T13:34:10.374Z

Status : Analyzed
Published: 2024-09-17T12:15:02.977
Modified: 2025-07-30T16:22:43.363
Link: CVE-2024-5998

No data.