Disclosure summary
## Summary Langflow versions 1.3.0 through 1.10.2 contain a code-injection vulnerability in the Smart Transform (`LambdaFilterComponent`) component. Smart Transform places flow-author instructions and a preview of its input data into a prompt asking an LLM to generate a Python lambda. It then extracts a one-line lambda from the model response, applies only syntactic format checks, evaluates it with Python's full builtins, and invokes the resulting function inside the Langflow process. A malicious flow author can exploit this directly through the Instructions field. In deployments where an exposed flow passes attacker-controlled content into Smart Transform, an attacker may also exploit it indirectly through prompt injection, subject to the configured model following the injected instruction. ## Vulnerability details **Vulnerable Code Location**: `src/lfx/src/lfx/components/llm_operations/lambda_filter.py` (line 242 in v1.10.2) ```python def _validate_lambda(self, lambda_text: str) -> bool: """Validate the provided lambda function text.""" return lambda_text.strip().startswith("lambda") and ":" in lambda_text # ... return eval(lambda_text) # noqa: S307 ``` For example, an attacker c
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-9fpm-3445-2vx4
Open original source · Updated Oct 05, 2026
Langflow: Prompt injection in Langflow Smart Transform can lead to code execution
Source severity: HIGH / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| pip | langflow | >= 1.3.0, < 1.10.3 | 1.10.3 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-05T18:30:41-04:00
MODIFIED 2026-10-05T18:30:42-04:00
INGESTED 2026-10-06T11:45:33-04:00