Embedchain is a framework for building retrieval-augmented generation (RAG) applications, and its vulnerability profile centers on that single product with a durable signal in command-injection and regular-expression-complexity flaws. These weakness classes reflect the parsing and shell-interaction demands inherent to an LLM integration library that processes and executes user-supplied prompts. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Embedchain over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-23731CRITICAL The OpenAPI loader in Embedchain before 0.1.57 allows attackers to execute arbitrary code, related to the openapi.py yaml.load function argument. | Jan 21, 2024 | 9.8 | 30 | NO | NO |
CVE-2024-23732HIGH The JSON loader in Embedchain before 0.1.57 allows a ReDoS (regular expression denial of service) via a long string to json.py. | Jan 21, 2024 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Embedchain.
Media articles that mention a CVE ID that affects a product developed by Embedchain — matched by CVE ID, not by vendor name.