langflow is vulnerable to Code Injection
88
High Risk
Langflow’s Smart Transform LambdaFilterComponent validates only that a user-controlled expression begins with lambda and contains a colon before evaluating it with Python eval() and full builtins. A flow author or prompt-injected model output can execute arbitrary operating-system commands in the Langflow process. The fix replaces unsafe evaluation with constrained parsing and execution.
You are affected if you are using a version that falls within the vulnerable range and untrusted users or model output can configure Smart Transform lambda filters.
langflow is vulnerable to Code Injection in versions 1.3.0 - 1.10.2.
Upgrade the langflow library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.