CVE-2026-101861: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in langflow-ai langflow
Langflow 1.0.16 before 1.12.0 and 0.0.94 before 1.12.0 contain an unsafe eval() vulnerability in schema.py that allows authenticated attackers to achieve code execution by placing a Python object with a malicious __repr__ method into component input options lists. The eval() sink is triggered when a component is converted into a LangChain tool via ComponentToolkit.get_tools(), including during custom component saves through the API, by interpolating options into a Literal type string that is passed directly to eval() without safe evaluation controls.
AI Analysis
Technical Summary
CVE-2026-101861 describes an eval injection vulnerability in langflow-ai's langflow product affecting versions >=1.0.16 <1.12.0 and >=0.0.94 <1.12.0. The flaw exists in schema.py where an eval() call is used unsafely during the conversion of components into LangChain tools via ComponentToolkit.get_tools(). Authenticated attackers can place Python objects with malicious __repr__ methods into component input options lists, triggering arbitrary code execution when eval() processes these options interpolated into a Literal type string. This unsafe eval usage lacks proper sanitization or safe evaluation mechanisms.
Potential Impact
The vulnerability allows authenticated attackers with high privileges to execute arbitrary code on the system running langflow by exploiting the unsafe eval() call. The CVSS score is low (2.1) due to the requirement for high privileges and user interaction, and limited scope and impact. There are no known exploits in the wild. The impact is limited to authenticated users who can manipulate component input options.
Mitigation Recommendations
No official patch or remediation information is provided in the input data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict access to authenticated users and avoid using vulnerable versions if possible.
CVE-2026-101861: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in langflow-ai langflow
Description
Langflow 1.0.16 before 1.12.0 and 0.0.94 before 1.12.0 contain an unsafe eval() vulnerability in schema.py that allows authenticated attackers to achieve code execution by placing a Python object with a malicious __repr__ method into component input options lists. The eval() sink is triggered when a component is converted into a LangChain tool via ComponentToolkit.get_tools(), including during custom component saves through the API, by interpolating options into a Literal type string that is passed directly to eval() without safe evaluation controls.
CVSS v4.0
Score 2.1low
Affected software
langflow-ai
langflow
pkg:github/langflowRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-101861 describes an eval injection vulnerability in langflow-ai's langflow product affecting versions >=1.0.16 <1.12.0 and >=0.0.94 <1.12.0. The flaw exists in schema.py where an eval() call is used unsafely during the conversion of components into LangChain tools via ComponentToolkit.get_tools(). Authenticated attackers can place Python objects with malicious __repr__ methods into component input options lists, triggering arbitrary code execution when eval() processes these options interpolated into a Literal type string. This unsafe eval usage lacks proper sanitization or safe evaluation mechanisms.
Potential Impact
The vulnerability allows authenticated attackers with high privileges to execute arbitrary code on the system running langflow by exploiting the unsafe eval() call. The CVSS score is low (2.1) due to the requirement for high privileges and user interaction, and limited scope and impact. There are no known exploits in the wild. The impact is limited to authenticated users who can manipulate component input options.
Mitigation Recommendations
No official patch or remediation information is provided in the input data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict access to authenticated users and avoid using vulnerable versions if possible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-28T15:44:45.388Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aba8fcff7a7c54106e608c7
Added to database: 09/28/2026, 16:03:27 UTC
Last enriched: 09/28/2026, 16:17:55 UTC
Last updated: 09/29/2026, 02:47:34 UTC
Views: 15
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.