Unsafe Code Execution Vulnerability in Langflow Product by Langflow AI
CVE-2026-101861

2.1LOW

Key Information:

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-101861?

Langflow versions 1.0.16 and 0.0.94 prior to 1.12.0 exhibit a vulnerability in schema.py that permits authenticated attackers to exploit the unsafe use of eval(). By injecting a Python object with a malicious repr method into component input options lists, attackers can trigger the eval() function. This occurs during the conversion of a component into a LangChain tool via the ComponentToolkit.get_tools() method, particularly when saving custom components through the API. The lack of safe evaluation controls significantly increases the risk of code execution, necessitating immediate attention.

Affected Version(s)

langflow 1.0.16 < 1.12.0

langflow 0.0.94 < 1.12.0

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Weblover
VulnCheck
.