SCA: security update for langchain-experimental (GHSA-cgcg-p68q-3w7v)

critical Tenable Cloud Security Plugin ID 413891

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Versions of the package langchain-experimental from 0.0.15 and before 0.0.21 are vulnerable to Arbitrary
Code Execution when retrieving values from the database, the code will attempt to call 'eval' on all
values. An attacker can exploit this vulnerability and execute arbitrary python code if they can control
the input prompt and the server is configured with VectorSQLDatabaseChain. **Notes:** Impact on the
Confidentiality, Integrity and Availability of the vulnerable component: Confidentiality: Code execution
happens within the impacted component, in this case langchain-experimental, so all resources are
necessarily accessible. Integrity: There is nothing protected by the impacted component inherently.
Although anything returned from the component counts as 'information' for which the trustworthiness can be
compromised. Availability: The loss of availability isn't caused by the attack itself, but it happens as a
result during the attacker's post-exploitation steps. Impact on the Confidentiality, Integrity and
Availability of the subsequent system: As a legitimate low-privileged user of the package (PR:L) the
attacker does not have more access to data owned by the package as a result of this vulnerability than
they did with normal usage (e.g. can query the DB). The unintended action that one can perform by breaking
out of the app environment and exfiltrating files, making remote connections etc. happens during the post
exploitation phase in the subsequent system - in this case, the OS. AT:P: An attacker needs to be able to
influence the input prompt, whilst the server is configured with the VectorSQLDatabaseChain plugin.
(CVE-2024-21513)

See Also

https://github.com/advisories/GHSA-cgcg-p68q-3w7v

Plugin Details

Severity: Critical

ID: 413891

Version: Revision 1.14

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: High

Score: 7.7

Percentile: 99.1

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: High

Base Score: 7.1

Temporal Score: 5.6

Vector: CVSS2#AV:N/AC:H/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2024-21513

CVSS v3

Risk Factor: High

Base Score: 8.5

Temporal Score: 7.6

Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

Risk Factor: Critical

Base Score: 9

Threat Score: 7.5

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 7/15/2024

Vulnerability Publication Date: 7/15/2024

Reference Information

CVE: CVE-2024-21513

cwe: CWE-94