What happened
Langflow's schema handling evaluates untrusted Python during component input-options introspection, letting an authenticated attacker execute code on the platform server by planting a malicious __repr__ object into an options list. Fixed in 1.12.0 alongside a broad security hardening release.
Why it matters
In a multi-tenant LLM application platform, authenticated code execution means a low-privileged user can escalate to full server control — reading prompt/pipeline secrets, model API keys, and vector data — which is the model of compromise that matters most for deployed LLM orchestrators.
Attack vector
An unsafe eval() sink in schema.py is triggered when component input option lists are processed; a crafted object whose __repr__ carries an attack expression is evaluated on the server when schema introspection runs — authenticated but remote, affecting shared Langflow instances.
Affected systems
Langflow 1.0.16 before 1.12.0 and 0.0.94 before 1.12.0 (schema.py)
Mitigation
Upgrade to Langflow 1.12.0 or later; the 1.12.x release train also closed multiple related code-scanner, sandbox-escape, cache deserialization (H1-3982189), and SSRF gaps in component code scanning and connectors.