CRITICAL 9.9 GitHub
CVE-2026-10561
Langflow: PythonREPLComponent executes unsandboxed Python code, enabling authenticated RCE and privilege escalation
### Summary
Langflow's built-in Python interpreter components — `PythonREPLComponent` (Python Interpreter) and the legacy `PythonREPLToolComponent` (Python REPL Tool) — executed arbitrary user- or model-supplied Python code inside flows without effective sandboxing. Because the code ran in-process with the privileges of the Langflow service, any **authenticated** user who could edit and run a flow could achieve remote code execution and, from there, escalate privileges to superuser (e.g. by ope
Affected Products
- pip/langflow < 1.10.1
References
- https://github.com/advisories/GHSA-8qpj-27x8-pwpq
- https://github.com/langflow-ai/langflow/security/advisories/GHSA-8qpj-27x8-pwpq
- https://nvd.nist.gov/vuln/detail/CVE-2026-10561
- https://github.com/langflow-ai/langflow/pull/13700
This critical severity vulnerability with a CVSS score of 9.9 was published on 2026-10-06 via GitHub. Affected: pip/langflow < 1.10.1.
Risk Timeline
CVE Disclosed2026-10-06 · -1 days ago
Remediation Resources
NVD / MITRE
nvd.nist.gov/vuln/detail/CVE-2026-10561Related Vulnerabilities
| CVE | Title | Severity | CVSS |
|---|---|---|---|
| CVE-2026-8505 | Langflow: Unauthenticated Flow Execution via Webhook Authentication Bypass | CRITICAL | 9.8 |
| CVE-2026-9205 | Langflow: Weak Fernet Key via random.seed() | CRITICAL | 9.1 |
| CVE-2026-102268 | PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public ke | CRITICAL | 9.1 |
| CVE-2026-7700 | Langflow: Prompt injection in Langflow Smart Transform can lead to code executio | HIGH | 8.8 |
| CVE-2026-71416 | Headroom vulnerable to Cross-Site WebSocket Hijacking (CSWSH) | HIGH | 8.8 |
| CVE-2026-87817 | GitPython: Repository content can impersonate the git directory, leading to arbi | HIGH | 8.8 |
vulnfeed aggregates 9311 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.