CVE-2026-101861 Overview
Langflow versions 1.0.16 before 1.12.0 and 0.0.94 before 1.12.0 contain an unsafe eval() vulnerability in schema.py. Authenticated attackers can achieve code execution by placing a Python object with a malicious __repr__ method into a component input options list. The eval() sink triggers when a component is converted into a LangChain tool via ComponentToolkit.get_tools(), including during custom component saves through the API. The vulnerability is categorized as code injection [CWE-94].
Critical Impact
Authenticated attackers can execute arbitrary Python code within the Langflow process by injecting a crafted object whose __repr__ output is interpolated into a Literal type string and passed to eval() without sanitization.
Affected Products
- Langflow versions 1.0.16 through 1.11.x
- Langflow versions 0.0.94 through 1.11.x
- Fixed in Langflow 1.12.0
Discovery Timeline
- 2026-09-28 - CVE-2026-101861 published to NVD
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-101861
Vulnerability Analysis
The vulnerability resides in schema.py within the Langflow codebase. When a component is converted into a LangChain tool through ComponentToolkit.get_tools(), the code constructs a Python Literal type annotation string by interpolating option values from component input definitions. The resulting string is then passed directly to eval() for evaluation.
Because interpolation calls repr() on each option value, any Python object placed in the options list controls the final string content through its __repr__ method. An attacker who can submit or save a custom component supplies an object whose __repr__ returns arbitrary Python expressions. Those expressions execute inside the Langflow server process when eval() runs.
The sink activates during routine operations, including API-driven custom component saves, so the vulnerable path is reachable without additional user interaction once an attacker is authenticated.
Root Cause
The root cause is unsafe dynamic code evaluation. The developers used eval() to materialize a type annotation at runtime rather than constructing the Literal object through safe type-system APIs such as typing.Literal[...]. No allowlist or sanitization validates the interpolated option values before evaluation.
Attack Vector
Exploitation requires network access to the Langflow API and valid authenticated credentials with permission to create or modify components. The attacker crafts a component input definition whose options list contains a malicious Python object. On save or tool conversion, the server evaluates attacker-controlled code. See the GitHub Security Advisory GHSA-33p4-w7j3-33mw for technical details.
No verified public exploit code is available at this time.
Detection Methods for CVE-2026-101861
Indicators of Compromise
- Unexpected custom component save requests to the Langflow API from authenticated users
- Child processes spawned by the Langflow server process that are inconsistent with normal workflow execution
- Outbound network connections initiated by the Langflow runtime to attacker-controlled infrastructure
- Modifications to component definitions containing unusual string content in input options fields
Detection Strategies
- Audit Langflow API logs for POST and PATCH requests targeting custom component endpoints and correlate with the submitting user identity
- Inspect stored component definitions for options list entries that are not simple string or numeric literals
- Monitor for calls into ComponentToolkit.get_tools() paired with exceptions originating from eval() in schema.py
Monitoring Recommendations
- Enable process-level telemetry on hosts running Langflow and alert on new child processes of the Python interpreter running the server
- Forward Langflow application logs and API access logs to a centralized analytics platform for correlation
- Track authentication events for Langflow accounts, especially new or recently elevated users creating components
How to Mitigate CVE-2026-101861
Immediate Actions Required
- Upgrade Langflow to version 1.12.0 or later as published in the GitHub Release v1.12.0
- Rotate credentials and API tokens for any Langflow accounts that may have been exposed
- Review existing custom components for unexpected or non-literal options values and remove suspicious entries
- Restrict component creation privileges to trusted users only
Patch Information
The vendor fixed the vulnerability in Langflow 1.12.0. The patch replaces the unsafe eval() based construction of the Literal type with a safe evaluation path. See the GitHub Security Advisory GHSA-33p4-w7j3-33mw for remediation details.
Workarounds
- Place Langflow behind an authenticated reverse proxy and limit API access to a small set of trusted IP addresses
- Disable or restrict custom component creation for non-administrative users until patching completes
- Run the Langflow process as an unprivileged user inside a container with no outbound internet access to limit the blast radius of code execution
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.