Skip to content
MediumVulnerability

CVE-2026-101861: Langflow code execution through unsafe eval() in schema.py

Identifier
CVE-2026-101861
Published
Record updated
View JSON
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.2%

Summary

Langflow versions 1.0.16 before 1.12.0 and 0.0.94 before 1.12.0 contain an unsafe eval() call in schema.py (CVE-2026-101861). An authenticated attacker can achieve code execution by placing a Python object with a malicious __repr__ method into component input options lists. The eval() runs when a component is converted into a LangChain tool via ComponentToolkit.get_tools(), including during custom component saves through the API.

Mitigation

Fixed in 1.12.0.