Description
A path traversal vulnerability exists in the getFullPath method of langchain-ai/langchainjs version 0.2.5. This vulnerability allows attackers to save files anywhere in the filesystem, overwrite existing text files, read .txt files, and delete files.
Recommendation
Update the langchain package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.2.19
- Patched version(s): 0.2.19
References
Related Issues
- Agnai File Disclosure Vulnerability: JSON via Path Traversal - CVE-2024-47170
- Saltcorn Server allows logged-in users to delete arbitrary files because of a path traversal vulnerability - CVE-2024-47818
- Jan path traversal vulnerability - @janhq/core - CVE-2024-36858
- Jan path traversal vulnerability - CVE-2024-37273
You might also like:
- Tags:
- npm
- langchain
Anything's wrong? Let us know Last updated on November 01, 2024


