CVE-2023-34540

Source
https://cve.org/CVERecord?id=CVE-2023-34540
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-34540.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-34540
Aliases
Published
2023-06-14T00:00:00Z
Modified
2026-08-12T03:51:32.070845419Z
Summary
[none]
Details

Langchain before v0.0.225 was discovered to contain a remote code execution (RCE) vulnerability in the component JiraAPIWrapper (aka the JIRA API wrapper). This vulnerability allows attackers to execute arbitrary code via crafted input. As noted in the "releases/tag" reference, a fix is available.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/34xxx/CVE-2023-34540.json",
    "cna_assigner": "mitre"
}
References

Affected packages

Git / github.com/langchain-ai/langchain

Affected ranges

Type
GIT
Repo
https://github.com/langchain-ai/langchain
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0.0.171"
        },
        {
            "last_affected": "0.0.171"
        }
    ],
    "cpe": "cpe:2.3:a:langchain:langchain:0.0.171:*:*:*:*:*:*:*",
    "source": [
        "CPE_STRING",
        "REFERENCES"
    ]
}

Affected versions

0.*
0.0.171
v0.*
v0.0.171
v0.0.172
v0.0.173
v0.0.174
v0.0.175
v0.0.177
v0.0.178
v0.0.179
v0.0.180
v0.0.181
v0.0.182
v0.0.183
v0.0.184
v0.0.185
v0.0.186
v0.0.187
v0.0.188
v0.0.189
v0.0.190
v0.0.191
v0.0.192
v0.0.193
v0.0.194
v0.0.195
v0.0.196
v0.0.197
v0.0.198
v0.0.199
v0.0.200
v0.0.201
v0.0.202
v0.0.204
v0.0.205
v0.0.206
v0.0.207
v0.0.208
v0.0.209
v0.0.210
v0.0.211
v0.0.212
v0.0.213
v0.0.214
v0.0.215
v0.0.216
v0.0.217
v0.0.218
v0.0.219
v0.0.220
v0.0.221
v0.0.222
v0.0.223
v0.0.224

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-34540.json"