CVE-2026-51886
published 2026-10-01CVE-2026-51886: langflow-ai langflow v1.9.3 is affected by: Code Injection. The impact is: execute arbitrary code (remote). The component is…
PriorityP183critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
0.40%
32.4th percentile
langflow-ai langflow v1.9.3 is affected by: Code Injection. The impact is: execute arbitrary code (remote). The component is: src/backend/base/langflow/api/v1/validate.py:validate-post_validate_code-a-real-authenticated-http-post-to-api-v1. The attack vector is: Attack surface: HTTP or browser-backed service path. A public-facing route accepts raw Python source and forwards it into a server-side compile/exec validation path without any visible entitlement guard. ¶¶ A weakness has been identified in langflow-ai langflow up to 1.9.3. langflow contains a code injection vulnerability in validate-post_validate_code-a-real-authenticated-http-post-to-api-v1 (src/backend/base/langflow/api/v1/validate.py:13). An authenticated attacker can execute arbitrary Python code on the server by submitting malicious code to the /api/v1/validate/code endpoint, which directly executes user-supplied code without sandboxing or security controls.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| langflow | langflow | >= 1.7.2 < 1.10.1 | 1.10.1 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Langflow: Title Authenticated Remote Code Execution in validate_code via Malicious Decorators Description
ghsa·2026-10-05
CVE-2026-51886 [HIGH] CWE-94 Langflow: Title Authenticated Remote Code Execution in validate_code via Malicious Decorators Description
Langflow: Title Authenticated Remote Code Execution in validate_code via Malicious Decorators Description
###Summary:
A critical Authenticated Remote Code Execution (RCE) vulnerability exists in the validate_code function of Langflow. The` /api/v1/validate/code` endpoint, meant to validate user-supplied code, leverages Python's exec() function. While it attempts to restrict execution to function definitions, it fails to account for decorators, which are evaluated at definition time. This allows any authenticated user to execute arbitrary code on the server, resulting in a full system compromise.
### Details
The vulnerability is located in `src/lfx/src/lfx/custom/validate.py(exposed via src/backend/base/langflow/api/v1/validate.py`).
The validate_code function parses user input using as
GHSA
langflow-ai langflow v1.9.3 is affected by: Code Injection.
ghsa_unreviewed·2026-10-02
CVE-2026-51886 langflow-ai langflow v1.9.3 is affected by: Code Injection.
langflow-ai langflow v1.9.3 is affected by: Code Injection. The impact is: execute arbitrary code (remote). The component is: src/backend/base/langflow/api/v1/validate.py:validate-post_validate_code-a-real-authenticated-http-post-to-api-v1. The attack vector is: Attack surface: HTTP or browser-backed service path. A public-facing route accepts raw Python source and forwards it into a server-side compile/exec validation path without any visible entitlement guard. ¶¶ A weakness has been identified in langflow-ai langflow up to 1.9.3. langflow contains a code injection vulnerability in validate-post_validate_code-a-real-authenticated-http-post-to-api-v1 (src/backend/base/langflow/api/v1/validate.py:13). An authenticated attacker can execute arbitrary Python code on the server by submitting ma
VulDB
langflow-ai Langflow up to 1.9.3 Code Validation Endpoint validate.py post_validate_code code injection
vuldb·2026-10-02
CVE-2026-51886 [CRITICAL] langflow-ai Langflow up to 1.9.3 Code Validation Endpoint validate.py post_validate_code code injection
A vulnerability, which was classified as critical, has been found in langflow-ai Langflow up to 1.9.3. This vulnerability affects the function post_validate_code of the file src/backend/base/langflow/api/v1/validate.py of the component Code Validation Endpoint. Performing a manipulation results in code injection.
This vulnerability was named CVE-2026-51886. The attack may be initiated remotely. There is no available exploit.
VulnCheck
Langflow Langflow Improper Control of Generation of Code ('Code Injection')
vulncheck·2026·CVSS 9.8
CVE-2026-51886 [CRITICAL] Langflow Langflow Improper Control of Generation of Code ('Code Injection')
Langflow Langflow Improper Control of Generation of Code ('Code Injection')
langflow-ai langflow v1.9.3 is affected by: Code Injection. The impact is: execute arbitrary code (remote). The component is: src/backend/base/langflow/api/v1/validate.py:validate-post_validate_code-a-real-authenticated-http-post-to-api-v1. The attack vector is: Attack surface: HTTP or browser-backed service path. A public-facing route accepts raw Python source and forwards it into a server-side compile/exec validation path without any visible entitlement guard. ¶¶ A weakness has been identified in langflow-ai langflow up to 1.9.3. langflow contains a code injection vulnerability in validate-post_validate_code-a-real-authenticated-http-post-to-api-v1 (src/backend/base/langflow/api/v1/validate.py:13). An authentica
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-10-01
Published
Exploited in the wild