Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | LangChain ÐòÁл¯×¢ÈëÎó²îµ¼ÖÂÃô¸ÐÐÅϢй¶ |
CVE ID | CVE-2025-68664 |
Îó²îÀàÐÍ | ·´ÐòÁл¯×¢Èë | ·¢Ã÷ʱ¼ä | 2025-12-25 |
Îó²îÆÀ·Ö | 9.3 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
LangChainÊÇÒ»¸öÃæÏò´óÓïÑÔÄ£×Ó£¨LLM£©µÄÓ¦Óÿª·¢¿ò¼Ü£¬ÌṩÁ´Ê½Å²Óá¢ÌáÐÑÄ£°å¡¢Ó°ÏóÖÎÀí¡¢¹¤¾ßÓëÊðÀíµÈÄÜÁ¦£¬×ÊÖú¿ª·¢Õ߸ßЧ¹¹½¨¡¢±àÅźͰ²ÅÅ»ùÓÚLLMµÄÖØ´óÓ¦Óã¬ÆÕ±éÓÃÓÚ¶Ô»°ÏµÍ³¡¢ÖªÊ¶¼ìË÷ÓëÖÇÄÜ×Ô¶¯»¯³¡¾°¡£
2025Äê12ÔÂ25ÈÕ£¬×ðÁú¿Ê±¼¯ÍÅVSRC¼à²âµ½LangChainÐòÁл¯×¢ÈëÎó²î£¬¸ÃÎó²îÔ´ÓÚdumps()Óëdumpd()º¯ÊýÔÚ´¦Öóͷ£×ÔÓÉ×Öµäʱδ׼ȷתÒå°üÀ¨¡°lc¡±Òªº¦×ÖµÄÓû§¿É¿ØÊý¾Ý£¬µ¼ÖÂÆäÔÚload()»òloads()·´ÐòÁл¯Àú³ÌÖб»Îóʶ±ðΪÕýµ±µÄLangChain¹¤¾ß½á¹¹¡£¹¥»÷Õß¿Éͨ¹ýÔÚLLMÏìÓ¦¡¢metadata¡¢additional_kwargsµÈ¿É¿Ø×Ö¶ÎÖÐ×¢ÈëÌØÖÆÐòÁл¯½á¹¹£¬ÊµÏÖÃôÇéÐ÷ÐαäÁ¿Ð¹Â¶£¬»òÔÚÊÜÐÅÃüÃû¿Õ¼äÄÚʵÀý»¯¾ßÓи±×÷ÓõÄÀà¡£¸ÃÎó²îÓ°Ïì¶à¸öÄÚ²¿ÐòÁл¯Å²Óó¡¾°£¬Ôھɰ汾ĬÈÏ¿ªÆôsecrets_from_envµÄÇéÐÎÏÂΣº¦ÓÈΪͻ³ö¡£
¶þ¡¢Ó°Ïì¹æÄ£
1.0.0 <= langchain < 1.2.5
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
¹Ù·½ÒÑÐû²¼ÐÞ¸´²¹¶¡£¬ÒÔÐÞ¸´¸ÃÎó²î¡£
ÏÂÔØÁ´½Ó£ºhttps://github.com/langchain-ai/langchain/releases/
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£
3.3 ͨÓý¨Òé
? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬ïÔÌϵͳÎó²î£¬ÌáÉý·þÎñÆ÷µÄÇå¾²ÐÔ¡£? ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬Ð޸ķÀ»ðǽսÂÔ£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬ïÔ̽«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬ïÔ̹¥»÷Ãæ¡£? ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£? ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£? ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£
3.4 ²Î¿¼Á´½Ó
https://nvd.nist.gov/vuln/detail/CVE-2025-68664/https://github.com/langchain-ai/langchain/security/advisories/GHSA-c67j-w6g6-q2cm