langchainexperimental (aka LangChain Experimental) in LangChain before 0.0.306 allows an attacker to bypass the CVE-2023-36258 fix and execute arbitrary code via import in Python code, which is not prohibited by palchain/base.py.
{
"github_reviewed": true,
"github_reviewed_at": "2023-10-10T21:19:42Z",
"nvd_published_at": "2023-10-09T20:15:10Z",
"cwe_ids": [],
"severity": "CRITICAL"
}