HIGH 8.8 GitHub
CVE-2026-7700
Langflow: Prompt injection in Langflow Smart Transform can lead to code execution
## Summary
Langflow versions 1.3.0 through 1.10.2 contain a code-injection vulnerability in the Smart Transform (`LambdaFilterComponent`) component.
Smart Transform places flow-author instructions and a preview of its input data into a prompt asking an LLM to generate a Python lambda. It then extracts a one-line lambda from the model response, applies only syntactic format checks, evaluates it with Python's full builtins, and invokes the resulting function inside the Langflow process.
A malic
Affected Products
- pip/langflow >= 1.3.0, < 1.10.3
References
- https://github.com/advisories/GHSA-9fpm-3445-2vx4
- https://github.com/langflow-ai/langflow/security/advisories/GHSA-9fpm-3445-2vx4
- https://nvd.nist.gov/vuln/detail/CVE-2026-7700
- https://github.com/langflow-ai/langflow/pull/13530
This high severity vulnerability with a CVSS score of 8.8 was published on 2026-10-05 via GitHub. Affected: pip/langflow >= 1.3.0, < 1.10.3.
vulnfeed aggregates 7729 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.