CVE-2026-10561 is a critical vulnerability affecting langflow versions ** `< 1 in Langflow's PythonREPLComponent with a CVSS score of 9.9, enabling authenticated remote code execution and privilege escalation due to unsandboxed execution of arbitrary user-supplied Python code inside flows without effective sandboxing. The flaw type is code injection (CWE-94/CWE-95), and the attack vector is network access (AV:N). This vulnerability allows any authenticated user to execute arbitrary Python/OS commands with the Langflow service's privileges, escalate their own account to superuser via direct database access, read/modify data and configuration, and potentially pivot to the underlying host. The affected version range is less than 1.10.1, and the issue is fixed as of 1.10.1 with additional hardening through 1.12.3.
We recommend you to update langflow to version 1.10.1.[/subscribe_to_unlock_form]
CVE-2026-10561 is a critical vulnerability affecting langflow versions ** `< 1 in Langflow's PythonREPLComponent with a CVSS score of 9.9, enabling authenticated remote code execution and privilege escalation due to unsandboxed execution of arbitrary user-supplied Python code inside flows without effective sandboxing. The flaw type is code injection (CWE-94/CWE-95), and the attack vector is network access (AV:N). This vulnerability allows any authenticated user to execute arbitrary Python/OS commands with the Langflow service's privileges, escalate their own account to superuser via direct database access, read/modify data and configuration, and potentially pivot to the underlying host. The affected version range is less than 1.10.1, and the issue is fixed as of 1.10.1 with additional hardening through 1.12.3.
We recommend you to update langflow to version 1.10.1.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]