Vulnerabilities/

Langchain Path Traversal vulnerability

Severity:
Medium

Description

A path traversal vulnerability exists in the getFullPath method of langchain-ai/langchainjs version 0.2.5. This vulnerability allows attackers to save files anywhere in the filesystem, overwrite existing text files, read .txt files, and delete files.

Recommendation

Update the langchain package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
langchain
Anything's wrong? Let us know Last updated on November 01, 2024

This issue is available in SmartScanner Professional

See Pricing