Disclosure summary
### Summary Langflow's built-in Python interpreter components — `PythonREPLComponent` (Python Interpreter) and the legacy `PythonREPLToolComponent` (Python REPL Tool) — executed arbitrary user- or model-supplied Python code inside flows without effective sandboxing. Because the code ran in-process with the privileges of the Langflow service, any **authenticated** user who could edit and run a flow could achieve remote code execution and, from there, escalate privileges to superuser (e.g. by opening a database session and flipping `is_superuser`) or compromise the host. **This issue is fixed as of 1.10.1**, with additional hardening through 1.12.3. See *Remediation* below. ### Affected - **Package:** `langflow` (PyPI), and the underlying `lfx` package that ships the component. - **Vulnerable versions:** `< 1.10.1`. - **Patched:** `1.10.1` (core fix). Upgrade to `>= 1.12.3` for the complete hardening series. ### Details The root cause is **code injection** (CWE-94/CWE-95): the component passed raw input to LangChain's `PythonREPL`, which is explicitly *not* a security sandbox. Two distinct weaknesses existed before 1.10.1: 1. **Unrestricted builtins (default deployments).** `get_glob
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-8qpj-27x8-pwpq
Open original source · Updated Oct 06, 2026
Langflow: PythonREPLComponent executes unsandboxed Python code, enabling authenticated RCE and privilege escalation
Source severity: CRITICAL / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| pip | langflow | < 1.10.1 | 1.10.1 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-06T09:38:28-04:00
MODIFIED 2026-10-06T09:38:29-04:00
INGESTED 2026-10-06T11:45:43-04:00