PT-2026-1999 · Langflow+1 · Langflow

·

CVE-2026-0769

·

Published

2026-01-09

·

Updated

2026-08-24

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Langflow (affected versions not specified)
Description Remote attackers can execute arbitrary code on affected installations without requiring authentication. The issue stems from a lack of proper validation of a user-supplied string within the eval custom component code() function before it is used to execute Python code. This allows an attacker to run code within the context of the current process.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider disabling the eval custom component code() function to minimize the risk of exploitation.

Exploit

RCE

Eval Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-0769
ZDI-26-035

Affected Products

Langflow