GHSA-8qpj-27x8-pwpq: Langflow: PythonREPLComponent executes unsandboxed Python code, enabling authenticated RCE and privilege escalation
- Identifiers
- CVE-2026-10561GHSA-8qpj-27x8-pwpq
- Published
- Record updated
Summary
Langflow's PythonREPLComponent and legacy PythonREPLToolComponent executed user- or model-supplied Python without effective sandboxing, so any authenticated user who could run a flow could gain code execution with the service's privileges and escalate to superuser by flipping is_superuser in the database. The root cause is CWE-94/CWE-95, with unrestricted builtins exposed even under the default allow_custom_components=True setting. Affected versions are below 1.10.1.
Mitigation
Upgrade langflow to 1.10.1 or later, preferably 1.12.3 or later. The fix adds restricted builtins via safe_builtins(), AST validation in validate_code_safety(), and a server-policy gate in ensure_code_execution_enabled() that refuses execution when allow_custom_components=False or block_code_interpreter_components=True.
Related items
- CriticalCVE-2026-108263: Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow coSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- HighGHSA-cv3g-hj65-pcfh: PraisonAI: Shell command allowlist bypass via find -exec built-in actionSimilar attack · GitHub Advisory Database
- CriticalGHSA-9mp3-24cc-77mg: PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool CallsSimilar attack · GitHub Advisory Database