Unsafe Code Execution Vulnerability in Langflow Product by Langflow AI
CVE-2026-101861
2.1LOW
What is CVE-2026-101861?
Langflow versions 1.0.16 and 0.0.94 prior to 1.12.0 exhibit a vulnerability in schema.py that permits authenticated attackers to exploit the unsafe use of eval(). By injecting a Python object with a malicious repr method into component input options lists, attackers can trigger the eval() function. This occurs during the conversion of a component into a LangChain tool via the ComponentToolkit.get_tools() method, particularly when saving custom components through the API. The lack of safe evaluation controls significantly increases the risk of code execution, necessitating immediate attention.
Affected Version(s)
langflow 1.0.16 < 1.12.0
langflow 0.0.94 < 1.12.0
