HIGH 8.8 GitHub

CVE-2026-7700

Langflow: Prompt injection in Langflow Smart Transform can lead to code execution

## Summary Langflow versions 1.3.0 through 1.10.2 contain a code-injection vulnerability in the Smart Transform (`LambdaFilterComponent`) component. Smart Transform places flow-author instructions and a preview of its input data into a prompt asking an LLM to generate a Python lambda. It then extracts a one-line lambda from the model response, applies only syntactic format checks, evaluates it with Python's full builtins, and invokes the resulting function inside the Langflow process. A malic

Affected Products

References

Published: 2026-10-05 · Source: GitHub · Feed updated: 2026-10-06
This high severity vulnerability with a CVSS score of 8.8 was published on 2026-10-05 via GitHub. Affected: pip/langflow >= 1.3.0, < 1.10.3.
vulnfeed aggregates 7729 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.