What happened
NVD published (2026-10-01) a code-injection finding in Langflow's code-validation endpoint: user-supplied Python is executed server-side in a compile/exec validation path with no sandboxing, allowing authenticated (and in exposed deployments effectively any) callers to execute arbitrary code.
Why it matters
Langflow is used to build LLM/agent workflows and often hosts sensitive model/dataset connections; RCE on the server means an attacker can read the connected model-provider keys, RAG stores, and downstream credentials the AI stack relies on.
Attack vector
A user submits raw Python source to the /api/v1/validate/code endpoint, which forwards it into a server-side compile/exec validation path without a sandbox — resulting in arbitrary Python execution on the Langflow server.
Affected systems
langflow-ai langflow up to 1.9.3 (src/backend/base/langflow/api/v1/validate.py)
Mitigation
Monitor for the vendor fix (GitHub issue langflow-ai/langflow#13336); restrict network exposure of the /api/v1/validate/code route; run Langflow with least-privilege server access.