High severity7.5NVD Advisory· Published Jan 21, 2024· Updated Jun 17, 2026
CVE-2024-23732
CVE-2024-23732
Description
The JSON loader in Embedchain before 0.1.57 allows a ReDoS (regular expression denial of service) via a long string to json.py.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
embedchainPyPI | < 0.1.57 | 0.1.57 |
Affected products
3cpe:2.3:a:embedchain:embedchain:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:embedchain:embedchain:*:*:*:*:*:*:*:*range: <0.1.57
- (no CPE)
Patches
Vulnerability mechanics
References
5- github.com/embedchain/embedchain/compare/0.1.56...0.1.57nvdPatchWEB
- github.com/embedchain/embedchain/pull/1122nvdIssue TrackingPatchWEB
- github.com/advisories/GHSA-r67w-f99w-mgxjghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-23732ghsaADVISORY
- github.com/pypa/advisory-database/tree/main/vulns/embedchain/PYSEC-2024-8.yamlghsaWEB
News mentions
0No linked articles in our index yet.