Impact
The vulnerability lies in the use of an unsafe eval() call within Langflow’s schema.py. Authenticated users can supply a Python object that contains a malicious __repr__ method inside a component’s input options list. When the component is converted into a LangChain tool via ComponentToolkit.get_tools(), the object’s __repr__ is evaluated by eval() without any safety checks, allowing arbitrary Python code execution. This results in complete compromise of the host environment.
Affected Systems
Langflow managed by langflow‑ai: langflow. Versions affected are 1.0.16 and earlier, and 0.0.94 and earlier, up to just before the 1.12.0 release.
Risk and Exploitability
The CVSS score is 2.1, indicating a low severity rating. EPSS is not available and the vulnerability is not listed in KEV. Exploitation requires authentication and the ability to submit or edit component definitions via the API or UI. During conversion to a LangChain tool, the malicious __repr__ is evaluated by eval(), allowing the attacker to execute arbitrary Python code on the host.
OpenCVE Enrichment