What happened
NVD published CVE-2026-51886 on 2026-10-01 (MITRE, unrated): Langflow up to 1.9.3 contains a code-injection vulnerability in validate.py where the /api/v1/validate/code endpoint directly executes user-supplied Python without sandboxing — arbitrary remote code execution for an authenticated attacker.
Why it matters
Code-exec nodes are core to Langflow's agent/RAG workflows; an authenticated attacker gaining arbitrary Python execution on the server reaches the LLM pipeline host, the vector store, and any connected credentials — full AI-workflow-backend compromise of a popular open-source framework.
Attack vector
An authenticated HTTP POST to /api/v1/validate/code submits raw Python source that is forwarded into a server-side compile/exec validation path with no sandbox or entitlement guard, giving arbitrary remote code execution on the Langflow server.
Affected systems
Langflow <= 1.9.3
Mitigation
Apply upstream fix (langflow-ai/langflow issue #13336 / patched release); restrict authenticated access and network exposure of the API until patched.