-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from insufficient path validation in methods handling user-controlled keys. The patch specifically modifies the _get_full_path validation logic used by both mset and mget, and adds tests that explicitly target these methods with traversal payloads. The CVE description directly implicates these methods as the attack vectors for path traversal.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| langchain | pip | < 0.0.353 | 0.0.353 |
Ongoing coverage of React2Shell