{"data":{"id":"641a9849-8cec-41df-9eb8-711bfa3821e4","title":"CVE-2026-51886: langflow-ai langflow v1.9.3 is affected by: Code Injection. The impact is: execute arbitrary code (remote). The…","summary":"Langflow up to version 1.9.3 contains a code injection flaw in the validate-post_validate_code endpoint, implemented in src/backend/base/langflow/api/v1/validate.py. An authenticated attacker can submit Python code to /api/v1/validate/code, which executes it on the server without sandboxing or security controls, enabling arbitrary code execution. The source states the route accepts raw Python source without a visible entitlement guard.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-51886","publishedAt":"2026-10-01T22:17:03.387Z","cveId":"CVE-2026-51886","cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"critical","attackType":["other"],"issueType":"vulnerability","affectedPackages":["langflow@>= 1.7.2, < 1.10.1 (fixed: 1.10.1)"],"affectedPackageNames":["langflow"],"affectedVendors":[],"affectedVendorsRaw":["Langflow"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":"Langflow code injection in /api/v1/validate/code endpoint","headlinePromptVersion":"h1","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00403,"epssCheckedAt":"2026-10-10T06:41:58.710Z","kevDateAdded":null,"advisoryAliases":["GHSA-w584-2h2r-2hvf"],"affectedPackagesSource":"ghsa","affectedPackagesCheckedAt":"2026-10-10T03:43:03.250Z","patchAvailable":true,"disclosureDate":"2026-10-01T22:17:03.387Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"framework","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null}}