PT-2026-1999 · Langflow+1 · Langflow
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Langflow (affected versions not specified)
Description
Remote attackers can execute arbitrary code on affected installations without requiring authentication. The issue stems from a lack of proper validation of a user-supplied string within the
eval custom component code() function before it is used to execute Python code. This allows an attacker to run code within the context of the current process.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, consider disabling the
eval custom component code() function to minimize the risk of exploitation.Exploit
RCE
Eval Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Langflow