Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | LangChain ÐòÁл¯×¢ÈëÎó²îµ¼ÖÂÃô¸ÐÐÅϢй¶ |
CVE ID | CVE-2025-68664 |
Îó²îÀàÐÍ | ·´ÐòÁл¯×¢Èë | ·¢Ã÷ʱ¼ä | 2025-12-25 |
Îó²îÆÀ·Ö | 9.3 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
LangChainÊÇÒ»¸öÃæÏò´óÓïÑÔÄ£×Ó£¨LLM£©µÄÓ¦Óÿª·¢¿ò¼Ü£¬£¬£¬£¬£¬ÌṩÁ´Ê½Å²Óá¢ÌáÐÑÄ£°å¡¢Ó°ÏóÖÎÀí¡¢¹¤¾ßÓëÊðÀíµÈÄÜÁ¦£¬£¬£¬£¬£¬×ÊÖú¿ª·¢Õ߸ßЧ¹¹½¨¡¢±àÅźͰ²ÅÅ»ùÓÚLLMµÄÖØ´óÓ¦Ó㬣¬£¬£¬£¬ÆÕ±éÓÃÓÚ¶Ô»°ÏµÍ³¡¢ÖªÊ¶¼ìË÷ÓëÖÇÄÜ×Ô¶¯»¯³¡¾°¡£¡£¡£
2025Äê12ÔÂ25ÈÕ£¬£¬£¬£¬£¬ÄϹ¬NGÓéÀÖ¼¯ÍÅVSRC¼à²âµ½LangChainÐòÁл¯×¢ÈëÎó²î£¬£¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚdumps()Óëdumpd()º¯ÊýÔÚ´¦Öóͷ£×ÔÓÉ×Öµäʱδ׼ȷתÒå°üÀ¨¡°lc¡±Òªº¦×ÖµÄÓû§¿É¿ØÊý¾Ý£¬£¬£¬£¬£¬µ¼ÖÂÆäÔÚload()»òloads()·´ÐòÁл¯Àú³ÌÖб»Îóʶ±ðΪÕýµ±µÄLangChain¹¤¾ß½á¹¹¡£¡£¡£¹¥»÷Õß¿Éͨ¹ýÔÚLLMÏìÓ¦¡¢metadata¡¢additional_kwargsµÈ¿É¿Ø×Ö¶ÎÖÐ×¢ÈëÌØÖÆÐòÁл¯½á¹¹£¬£¬£¬£¬£¬ÊµÏÖÃôÇéÐ÷ÐαäÁ¿Ð¹Â¶£¬£¬£¬£¬£¬»òÔÚÊÜÐÅÃüÃû¿Õ¼äÄÚʵÀý»¯¾ßÓи±×÷ÓõÄÀà¡£¡£¡£¸ÃÎó²îÓ°Ïì¶à¸öÄÚ²¿ÐòÁл¯Å²Óó¡¾°£¬£¬£¬£¬£¬Ôھɰ汾ĬÈÏ¿ªÆôsecrets_from_envµÄÇéÐÎÏÂΣº¦ÓÈΪͻ³ö¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
1.0.0 <= langchain < 1.2.5
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
¹Ù·½ÒÑÐû²¼ÐÞ¸´²¹¶¡£¬£¬£¬£¬£¬ÒÔÐÞ¸´¸ÃÎó²î¡£¡£¡£
ÏÂÔØÁ´½Ó£ºhttps://github.com/langchain-ai/langchain/releases/
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£¡£¡£
3.3 ͨÓý¨Òé
? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬£¬£¬ïÔÌϵͳÎó²î£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£? ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬£¬ïÔ̹¥»÷Ãæ¡£¡£¡£? ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£? ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£? ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£
3.4 ²Î¿¼Á´½Ó
https://nvd.nist.gov/vuln/detail/CVE-2025-68664/https://github.com/langchain-ai/langchain/security/advisories/GHSA-c67j-w6g6-q2cm