High severity8.8NVD Advisory· Published Apr 16, 2024· Updated Jun 17, 2026
CVE-2024-3571
CVE-2024-3571
Description
langchain-ai/langchain is vulnerable to path traversal due to improper limitation of a pathname to a restricted directory ('Path Traversal') in its LocalFileStore functionality. An attacker can leverage this vulnerability to read or write files anywhere on the filesystem, potentially leading to information disclosure or remote code execution. The issue lies in the handling of file paths in the mset and mget methods, where user-supplied input is not adequately sanitized, allowing directory traversal sequences to reach unintended directories.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
langchainPyPI | < 0.0.353 | 0.0.353 |
Affected products
3unspecified+ 1 more
- (no CPE)range: unspecified
- cpe:2.3:a:langchain:langchain:0.0.351:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
4- github.com/langchain-ai/langchain/commit/aad3d8bd47d7f5598156ff2bdcc8f736f24a7412nvdPatchWEB
- huntr.com/bounties/2df3acdc-ee4f-4257-bbf8-a7de3870a9d8nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-rgp8-pm28-3759ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-3571ghsaADVISORY
News mentions
0No linked articles in our index yet.