{"data":{"id":"622c5e16-21c2-4d25-8cce-80721ef495bf","title":"GHSA-8qpj-27x8-pwpq: Langflow: PythonREPLComponent executes unsandboxed Python code, enabling authenticated RCE and privilege escalation","summary":"Langflow's PythonREPLComponent and legacy PythonREPLToolComponent executed user- or model-supplied Python without effective sandboxing, so any authenticated user who could run a flow could gain code execution with the service's privileges and escalate to superuser by flipping is_superuser in the database. The root cause is CWE-94/CWE-95, with unrestricted builtins exposed even under the default allow_custom_components=True setting. Affected versions are below 1.10.1.","solution":"Upgrade langflow to 1.10.1 or later, preferably 1.12.3 or later. The fix adds restricted builtins via safe_builtins(), AST validation in validate_code_safety(), and a server-policy gate in ensure_code_execution_enabled() that refuses execution when allow_custom_components=False or block_code_interpreter_components=True.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-8qpj-27x8-pwpq","publishedAt":"2026-10-06T13:38:28.000Z","cveId":"CVE-2026-10561","cweIds":null,"cvssScore":null,"cvssSeverity":"critical","severity":"critical","attackType":["other"],"issueType":"vulnerability","affectedPackages":["langflow@< 1.10.1 (fixed: 1.10.1)"],"affectedPackageNames":["langflow"],"affectedVendors":[],"affectedVendorsRaw":["Langflow"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.0082,"epssCheckedAt":"2026-10-10T06:41:58.184Z","kevDateAdded":null,"advisoryAliases":["GHSA-8qpj-27x8-pwpq"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2026-10-06T13:38:28.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"plugin","llmSpecific":false,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null}}