Vulnerability  ·  2026-10-03

Langflow code injection: /api/v1/validate/code executes arbitrary Python without sandbox (CVE-2026-51886)

VulnerabilityHigh impactGlobalCVE-2026-51886
NVD published CVE-2026-51886 on 2026-10-01 (MITRE, unrated): Langflow up to 1.9.3 contains a code-injection vulnerability in validate.py where the /api/v1/validate/code endpoint directly executes user-supplied Python without sandboxing — arbitrary remote code execution for an authenticated attacker.
Code-exec nodes are core to Langflow's agent/RAG workflows; an authenticated attacker gaining arbitrary Python execution on the server reaches the LLM pipeline host, the vector store, and any connected credentials — full AI-workflow-backend compromise of a popular open-source framework.
An authenticated HTTP POST to /api/v1/validate/code submits raw Python source that is forwarded into a server-side compile/exec validation path with no sandbox or entitlement guard, giving arbitrary remote code execution on the Langflow server.
Langflow <= 1.9.3
Apply upstream fix (langflow-ai/langflow issue #13336 / patched release); restrict authenticated access and network exposure of the API until patched.
NVD CVE-2026-51886Langflow issue #13336Ro1ME gist — Langflow code injection
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →