An issue in LangChain before 0.0.236 allows an attacker to execute arbitrary code because Python code with os.system, exec, or eval can be used.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-36258.json"