Intel

AIKIDO-2026-159862

langflow is vulnerable to Code Injection

Code InjectionGHSA-8qpj-27x8-pwpq Published Today

99

Critical Risk

This Affects:

PYTHONlangflow
1.1.0 - 1.10.0
Fixed in 1.10.1
Are you affected? Scan for Free

TL;DR

PythonREPLComponent and PythonREPLToolComponent pass Python from the flow into LangChain PythonREPL without replacing __builtins__, so the full builtins module is available. A signed-in user who can edit and run a flow can call __import__ and run operating system commands in the Langflow process, including database writes that set is_superuser. The fix installs a restricted builtins map and rejects unsafe syntax before the code runs.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and signed-in users can edit or run flows that include the Python interpreter components.

Background info

langflow is vulnerable to Code Injection in versions 1.1.0 - 1.10.0.

How to fix this

Upgrade the langflow library to the patch version. Upgrading to 1.12.3 or later also includes the later security hardening.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform