Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | LangChain ÐòÁл¯×¢ÈëÎó²îµ¼ÖÂÃô¸ÐÐÅϢй¶ |
CVE ID | CVE-2025-68664 |
Îó²îÀàÐÍ | ·´ÐòÁл¯×¢Èë | ·¢Ã÷ʱ¼ä | 2025-12-25 |
Îó²îÆÀ·Ö | 9.3 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
LangChainÊÇÒ»¸öÃæÏò´óÓïÑÔÄ£×Ó£¨LLM£©µÄÓ¦Óÿª·¢¿ò¼Ü£¬£¬£¬ÌṩÁ´Ê½Å²Óá¢ÌáÐÑÄ£°å¡¢Ó°ÏóÖÎÀí¡¢¹¤¾ßÓëÊðÀíµÈÄÜÁ¦£¬£¬£¬×ÊÖú¿ª·¢Õ߸ßЧ¹¹½¨¡¢±àÅźͰ²ÅÅ»ùÓÚLLMµÄÖØ´óÓ¦Ó㬣¬£¬ÆÕ±éÓÃÓÚ¶Ô»°ÏµÍ³¡¢ÖªÊ¶¼ìË÷ÓëÖÇÄÜ×Ô¶¯»¯³¡¾°¡£¡£¡£¡£¡£
2025Äê12ÔÂ25ÈÕ£¬£¬£¬Z6×ðÁú¿Ê±¼¯ÍÅVSRC¼à²âµ½LangChainÐòÁл¯×¢ÈëÎó²î£¬£¬£¬¸ÃÎó²îÔ´ÓÚdumps()Óëdumpd()º¯ÊýÔÚ´¦Öóͷ£×ÔÓÉ×Öµäʱδ׼ȷתÒå°üÀ¨¡°lc¡±Òªº¦×ÖµÄÓû§¿É¿ØÊý¾Ý£¬£¬£¬µ¼ÖÂÆäÔÚload()»òloads()·´ÐòÁл¯Àú³ÌÖб»Îóʶ±ðΪÕýµ±µÄLangChain¹¤¾ß½á¹¹¡£¡£¡£¡£¡£¹¥»÷Õß¿Éͨ¹ýÔÚLLMÏìÓ¦¡¢metadata¡¢additional_kwargsµÈ¿É¿Ø×Ö¶ÎÖÐ×¢ÈëÌØÖÆÐòÁл¯½á¹¹£¬£¬£¬ÊµÏÖÃôÇéÐ÷ÐαäÁ¿Ð¹Â¶£¬£¬£¬»òÔÚÊÜÐÅÃüÃû¿Õ¼äÄÚʵÀý»¯¾ßÓи±×÷ÓõÄÀà¡£¡£¡£¡£¡£¸ÃÎó²îÓ°Ïì¶à¸öÄÚ²¿ÐòÁл¯Å²Óó¡¾°£¬£¬£¬Ôھɰ汾ĬÈÏ¿ªÆôsecrets_from_envµÄÇéÐÎÏÂΣº¦ÓÈΪͻ³ö¡£¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
1.0.0 <= langchain < 1.2.5
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
¹Ù·½ÒÑÐû²¼ÐÞ¸´²¹¶¡£¬£¬£¬ÒÔÐÞ¸´¸ÃÎó²î¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£ºhttps://github.com/langchain-ai/langchain/releases/
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£¡£¡£¡£¡£
3.3 ͨÓý¨Òé
? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬ïÔÌϵͳÎó²î£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£? ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬ïÔ̹¥»÷Ãæ¡£¡£¡£¡£¡£? ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£? ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£? ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£
3.4 ²Î¿¼Á´½Ó
https://nvd.nist.gov/vuln/detail/CVE-2025-68664/https://github.com/langchain-ai/langchain/security/advisories/GHSA-c67j-w6g6-q2cm