Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-10561: Langflow lets anyone run arbitrary Python code

CVE-2026-10561 · published 3 months ago
Summary

Versions of Langflow from 1.0.0 to 1.9.3 do not properly isolate Python commands and skip authentication. This means an attacker could run any code on the server, potentially taking full control. Update to a patched version or apply the recommended configuration changes to block unauthorized code execution.

What to do
  • Update langflow to version 1.10.1.
Affected software
Ecosystem VendorProductAffected versions
pip – langflow < 1.10.1
Fix: upgrade to 1.10.1
Original advisory text
Langflow: PythonREPLComponent executes unsandboxed Python code, enabling authenticated RCE and privilege escalation
IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arbitrary code on the host system, resulting in complete compromise
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
10.0 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-94Code Injection
CWE-95Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
CWE-266Incorrect Privilege Assignment
Timeline
Published22 Jun 2026
Updated9 Oct 2026
First seen22 Jun 2026
Sources
Track software like this
Free during beta