AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-7700.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSHIGH / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 05, 2026

Disclosure summary

## Summary Langflow versions 1.3.0 through 1.10.2 contain a code-injection vulnerability in the Smart Transform (`LambdaFilterComponent`) component. Smart Transform places flow-author instructions and a preview of its input data into a prompt asking an LLM to generate a Python lambda. It then extracts a one-line lambda from the model response, applies only syntactic format checks, evaluates it with Python's full builtins, and invokes the resulting function inside the Langflow process. A malicious flow author can exploit this directly through the Instructions field. In deployments where an exposed flow passes attacker-controlled content into Smart Transform, an attacker may also exploit it indirectly through prompt injection, subject to the configured model following the injected instruction. ## Vulnerability details **Vulnerable Code Location**: `src/lfx/src/lfx/components/llm_operations/lambda_filter.py` (line 242 in v1.10.2) ```python def _validate_lambda(self, lambda_text: str) -> bool: """Validate the provided lambda function text.""" return lambda_text.strip().startswith("lambda") and ":" in lambda_text # ... return eval(lambda_text) # noqa: S307 ``` For example, an attacker c

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-9fpm-3445-2vx4

Open original source · Updated Oct 05, 2026

Langflow: Prompt injection in Langflow Smart Transform can lead to code execution

Source severity: HIGH / 0

EcosystemPackageAffected rangeFirst patched
piplangflow>= 1.3.0, < 1.10.31.10.3

Original records & references

PUBLISHED 2026-10-05T18:30:41-04:00
MODIFIED 2026-10-05T18:30:42-04:00
INGESTED 2026-10-06T11:45:33-04:00