Remote Code Execution Vulnerability in Langflow by Langflow
CVE-2026-0769
9.8CRITICAL
What is CVE-2026-0769?
The eval_custom_component_code function in Langflow is vulnerable to an eval injection, allowing unauthenticated remote attackers to execute arbitrary code. By exploiting this flaw, which stems from inadequate validation of user-supplied strings, an attacker can run Python code in the context of the current process. This security issue poses significant risks to the integrity of applications utilizing Langflow.
Affected Version(s)
Langflow 1.3.2
