漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
langchain-ai langgraph Task Result Cache _cache.py _freeze weak hash
Vulnerability Description
A vulnerability was determined in langchain-ai langgraph up to 1.2.4. The affected element is the function _freeze of the file libs/langgraph/langgraph/_internal/_cache.py of the component Task Result Cache. This manipulation of the argument default_cache_key causes use of weak hash. The attack is possible to be carried out remotely. The complexity of an attack is rather high. The exploitability is described as difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
可逆的单向哈希
Vulnerability Title
LangChain LangGraph 加密问题漏洞
Vulnerability Description
LangChain LangGraph是LangChain公司开源的一个大模型框架。 LangChain LangGraph 1.2.4及之前版本存在加密问题漏洞,该漏洞源于Task Result Cache组件中文件libs/langgraph/langgraph/_internal/_cache.py的函数_freeze对参数default_cache_key的操作导致使用弱哈希。
CVSS Information
N/A
Vulnerability Type
N/A