langflow is vulnerable to Remote Code Execution (RCE)
98
Critical Risk
eval_custom_component_code passes a caller-supplied Python string to create_class() / prepare_global_scope(), which exec()s top-level assignments and class bodies with no sanitization. An unauthenticated request that reaches a custom-component or public-flow build path can supply that string and run arbitrary Python in the Langflow process. The fix stops unauthenticated callers from feeding component code into that evaluation path.
You are affected if you are using a version that falls within the vulnerable range and expose Langflow so that unauthenticated callers can reach custom-component evaluation.
langflow is vulnerable to Remote Code Execution (RCE) in versions 0.0.19 - 1.8.3.
Upgrade the langflow library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.