CRITICAL 9.9 GitHub

CVE-2026-10561

Langflow: PythonREPLComponent executes unsandboxed Python code, enabling authenticated RCE and privilege escalation

### Summary Langflow's built-in Python interpreter components — `PythonREPLComponent` (Python Interpreter) and the legacy `PythonREPLToolComponent` (Python REPL Tool) — executed arbitrary user- or model-supplied Python code inside flows without effective sandboxing. Because the code ran in-process with the privileges of the Langflow service, any **authenticated** user who could edit and run a flow could achieve remote code execution and, from there, escalate privileges to superuser (e.g. by ope

Affected Products

References

Published: 2026-10-06 · Source: GitHub · Feed updated: 2026-10-06
This critical severity vulnerability with a CVSS score of 9.9 was published on 2026-10-06 via GitHub. Affected: pip/langflow < 1.10.1.

Risk Timeline

CVE Disclosed2026-10-06 · -1 days ago

Remediation Resources

Related Vulnerabilities

CVETitleSeverityCVSS
CVE-2026-8505Langflow: Unauthenticated Flow Execution via Webhook Authentication BypassCRITICAL9.8
CVE-2026-9205Langflow: Weak Fernet Key via random.seed()CRITICAL9.1
CVE-2026-102268PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keCRITICAL9.1
CVE-2026-7700Langflow: Prompt injection in Langflow Smart Transform can lead to code executioHIGH8.8
CVE-2026-71416Headroom vulnerable to Cross-Site WebSocket Hijacking (CSWSH)HIGH8.8
CVE-2026-87817GitPython: Repository content can impersonate the git directory, leading to arbiHIGH8.8
vulnfeed aggregates 9311 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.