Description
Langflow 1.0.16 before 1.12.0 and 0.0.94 before 1.12.0 contain an unsafe eval() vulnerability in schema.py that allows authenticated attackers to achieve code execution by placing a Python object with a malicious __repr__ method into component input options lists. The eval() sink is triggered when a component is converted into a LangChain tool via ComponentToolkit.get_tools(), including during custom component saves through the API, by interpolating options into a Literal type string that is passed directly to eval() without safe evaluation controls.
Published: 2026-09-28
Score: 2.1 Low
EPSS: n/a
KEV: No
Impact: Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability lies in the use of an unsafe eval() call within Langflow’s schema.py. Authenticated users can supply a Python object that contains a malicious __repr__ method inside a component’s input options list. When the component is converted into a LangChain tool via ComponentToolkit.get_tools(), the object’s __repr__ is evaluated by eval() without any safety checks, allowing arbitrary Python code execution. This results in complete compromise of the host environment.

Affected Systems

Langflow managed by langflow‑ai: langflow. Versions affected are 1.0.16 and earlier, and 0.0.94 and earlier, up to just before the 1.12.0 release.

Risk and Exploitability

The CVSS score is 2.1, indicating a low severity rating. EPSS is not available and the vulnerability is not listed in KEV. Exploitation requires authentication and the ability to submit or edit component definitions via the API or UI. During conversion to a LangChain tool, the malicious __repr__ is evaluated by eval(), allowing the attacker to execute arbitrary Python code on the host.

Generated by OpenCVE AI on September 28, 2026 at 18:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Langflow 1.12.0 or newer, which eliminates the unsafe eval() call and addresses CWE-95.
  • Audit and remove any custom component definitions that include __repr__ methods or other code capable of executing on the platform (CWE-94).
  • Restrict API access to trusted users and enforce code review before allowing component definitions to be saved, mitigating CWE-94 exploitation.

Generated by OpenCVE AI on September 28, 2026 at 18:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Langflow
Langflow langflow
Vendors & Products Langflow
Langflow langflow

Mon, 28 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description Langflow 1.0.16 before 1.12.0 and 0.0.94 before 1.12.0 contain an unsafe eval() vulnerability in schema.py that allows authenticated attackers to achieve code execution by placing a Python object with a malicious __repr__ method into component input options lists. The eval() sink is triggered when a component is converted into a LangChain tool via ComponentToolkit.get_tools(), including during custom component saves through the API, by interpolating options into a Literal type string that is passed directly to eval() without safe evaluation controls.
Title Langflow Code Execution via eval() in Component Input Schema
Weaknesses CWE-94
CWE-95
References
Metrics cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L'}

cvssV4_0

{'score': 2.1, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Langflow Langflow
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-28T15:49:14.349Z

Reserved: 2026-09-28T15:44:45.388Z

Link: CVE-2026-101861

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T16:17:13.157

Modified: 2026-09-28T16:17:13.157

Link: CVE-2026-101861

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T18:30:04Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')

  • CWE-95

    Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')