MediumVulnerability
CVE-2026-101861: Langflow code execution through unsafe eval() in schema.py
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-101861
- Published
- Record updated
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.2%
Summary
Langflow versions 1.0.16 before 1.12.0 and 0.0.94 before 1.12.0 contain an unsafe eval() call in schema.py (CVE-2026-101861). An authenticated attacker can achieve code execution by placing a Python object with a malicious __repr__ method into component input options lists. The eval() runs when a component is converted into a LangChain tool via ComponentToolkit.get_tools(), including during custom component saves through the API.
Mitigation
Fixed in 1.12.0.
Related items
- CriticalCVE-2026-108263: Astron Agent code-node execution as root through workflow run endpointsSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- CriticalHermes Agent - PKCE Session Takeover via Redirect-URI Parser ConfusionSimilar attack · Tenable Research Advisories
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- HighGHSA-cv3g-hj65-pcfh: PraisonAI: Shell command allowlist bypass via find -exec built-in actionSimilar attack · GitHub Advisory Database