CriticalVulnerability
CVE-2026-51886: Langflow code injection in /api/v1/validate/code endpoint
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-51886
- Published
- Record updated
- Affected
- langflow >= 1.7.2, < 1.10.1
- Fixed in
- 1.10.1
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.4%
Summary
Langflow up to version 1.9.3 contains a code injection flaw in the validate-post_validate_code endpoint, implemented in src/backend/base/langflow/api/v1/validate.py. An authenticated attacker can submit Python code to /api/v1/validate/code, which executes it on the server without sandboxing or security controls, enabling arbitrary code execution. The source states the route accepts raw Python source without a visible entitlement guard.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Related items
- CriticalCVE-2026-108263: Astron Agent code-node execution as root through workflow run endpointsSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- CriticalHermes Agent - PKCE Session Takeover via Redirect-URI Parser ConfusionSimilar attack · Tenable Research Advisories
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- HighGHSA-cv3g-hj65-pcfh: PraisonAI: Shell command allowlist bypass via find -exec built-in actionSimilar attack · GitHub Advisory Database