Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-101861

MEDIUM NVD
CVSS Score 4.1
Severity MEDIUM
Published Sep 28, 2026
Vendor unknown

Description

Langflow 1.0.16 before 1.12.0 and 0.0.94 before 1.12.0 contain an unsafe eval() vulnerability in schema.py that allows authenticated attackers to achieve code execution by placing a Python object with a malicious __repr__ method into component input options lists. The eval() sink is triggered when a component is converted into a LangChain tool via ComponentToolkit.get_tools(), including during custom component saves through the API, by interpolating options into a Literal type string that is passed directly to eval() without safe evaluation controls.

References