Vulnerability  ·  2026-09-29

Langflow unsafe eval() leads to authenticated code execution via malicious component __repr__

VulnerabilityHigh impactGlobalCVE-2026-101861
Langflow's schema handling evaluates untrusted Python during component input-options introspection, letting an authenticated attacker execute code on the platform server by planting a malicious __repr__ object into an options list. Fixed in 1.12.0 alongside a broad security hardening release.
In a multi-tenant LLM application platform, authenticated code execution means a low-privileged user can escalate to full server control — reading prompt/pipeline secrets, model API keys, and vector data — which is the model of compromise that matters most for deployed LLM orchestrators.
An unsafe eval() sink in schema.py is triggered when component input option lists are processed; a crafted object whose __repr__ carries an attack expression is evaluated on the server when schema introspection runs — authenticated but remote, affecting shared Langflow instances.
Langflow 1.0.16 before 1.12.0 and 0.0.94 before 1.12.0 (schema.py)
Upgrade to Langflow 1.12.0 or later; the 1.12.x release train also closed multiple related code-scanner, sandbox-escape, cache deserialization (H1-3982189), and SSRF gaps in component code scanning and connectors.
NVD CVE-2026-101861Langflow releases (v1.12.0)
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →