CVE-2024-21513 affects langchain-experimental versions from 0.0.15 through before 0.0.21. When retrieving values from the database, the vulnerable code attempts to call Python 'eval' on all values. If an attacker can control the input prompt and the server is configured to use VectorSQLDatabaseChain, they can cause attacker-controlled data to reach the unsafe 'eval' path and achieve arbitrary Python code execution within the application process.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a Proof-of-Concept (PoC) exploit for CVE-2024-21513, a remote code execution vulnerability in langchain-experimental. The exploit is implemented as a simple Flask web application that allows users to add (x, y) coordinates to a SQLite database and then query the database via a simulated LLM interface. The vulnerability arises because the y value from the database (which can be attacker-controlled) is passed directly to Python's eval() function without validation, allowing arbitrary code execution. The repository contains 7 files, with the main logic in app/main.py (Flask app), app/db.py (database helpers), and app/llm.py (mock LLM and SQL chain). The Dockerfile and docker-compose.yml provide containerization for safe testing. The main entry point is app/main.py, which exposes several HTTP endpoints: - '/' (add coordinates) - '/add' (submit coordinates) - '/query' (ask a question) - '/ask' (triggers the vulnerable eval()) - '/debug' (view database contents) The exploit works by submitting a malicious y value (e.g., print("You've been pwned!")) for x=10, then querying for x=10 via the /ask endpoint, which results in the code being executed on the server. The PoC is intended for demonstration and research purposes, and is not weaponized. The targeted product is langchain-experimental (Python), specifically the vulnerable use of eval() on untrusted SQL results.
This repository is a proof-of-concept (POC) exploit for CVE-2024-21513, targeting the langchain-experimental Python package (versions >=0.0.15 and <0.0.21). The vulnerability arises from the use of eval() on database values in the VectorSQLDatabaseChain component, allowing arbitrary code execution via crafted SQL queries. The repository contains 6 files: a Python application (app.py), Docker deployment files (Dockerfile, .dockerignore), environment configuration (.env), dependency list (requirements.txt), and documentation (README.md). The main exploit logic is in app.py, which launches a Streamlit web app that connects to a PostgreSQL database and allows users to submit SQL queries. The README provides detailed setup and exploitation instructions, including a sample payload that demonstrates code execution (printing 'hacked' on the server). Key endpoints include the local Streamlit web interface (port 8501), a healthcheck endpoint, and a remote PostgreSQL database hosted on Supabase. The .env file contains sensitive credentials for the database connection. The exploit demonstrates the risk of remote code execution if user input is not properly sanitized in applications using the vulnerable langchain-experimental component.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.