PT-2026-36703 · Langflow · Langflow
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
langflow versions prior to 1.8.5
Description
A remote code injection flaw exists in the LambdaFilterComponent. The issue is located within the
eval() function of the file src/lfx/src/lfx/components/llm operations/lambda filter.p, where improper manipulation can allow an attacker to execute arbitrary code.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, consider restricting the use of the
eval() function within the LambdaFilterComponent to minimize the risk of exploitation.Exploit
Code Injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Langflow