Vulnerability  ·  2026-10-03

Langflow: code injection in /api/v1/validate/code enables remote arbitrary Python execution

VulnerabilityHigh impactGlobalCVE-2026-51886
NVD published (2026-10-01) a code-injection finding in Langflow's code-validation endpoint: user-supplied Python is executed server-side in a compile/exec validation path with no sandboxing, allowing authenticated (and in exposed deployments effectively any) callers to execute arbitrary code.
Langflow is used to build LLM/agent workflows and often hosts sensitive model/dataset connections; RCE on the server means an attacker can read the connected model-provider keys, RAG stores, and downstream credentials the AI stack relies on.
A user submits raw Python source to the /api/v1/validate/code endpoint, which forwards it into a server-side compile/exec validation path without a sandbox — resulting in arbitrary Python execution on the Langflow server.
langflow-ai langflow up to 1.9.3 (src/backend/base/langflow/api/v1/validate.py)
Monitor for the vendor fix (GitHub issue langflow-ai/langflow#13336); restrict network exposure of the /api/v1/validate/code route; run Langflow with least-privilege server access.
NVD CVE-2026-51886GitHub issue langflow-ai/langflow#13336
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →