CVE-2026-0771

Langflow PythonFunction Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Attack vectors and exploitability will vary depending on the configuration of the product. The specific flaw exists within the handling of Python function components. Depending upon product configuration, an attacker may be able to introduce custom Python code into a workflow. An attacker can leverage this vulnerability to execute code in the context of the application. Was ZDI-CAN-27497.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:langflow:langflow:1.4.2:-:*:*:*:*:*:*

History

17 Jun 2026, 10:11

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad de Inyección de Código PythonFunction de Langflow con Ejecución Remota de Código. Esta vulnerabilidad permite a atacantes remotos ejecutar código arbitrario en instalaciones afectadas de Langflow. Los vectores de ataque y la explotabilidad variarán dependiendo de la configuración del producto. La falla específica existe dentro del manejo de los componentes de función Python. Dependiendo de la configuración del producto, un atacante podría ser capaz de introducir código Python personalizado en un flujo de trabajo. Un atacante puede aprovechar esta vulnerabilidad para ejecutar código en el contexto de la aplicación. Fue ZDI-CAN-27497.

18 Feb 2026, 19:05

Type Values Removed Values Added
References () https://www.zerodayinitiative.com/advisories/ZDI-26-037/ - () https://www.zerodayinitiative.com/advisories/ZDI-26-037/ - Third Party Advisory
CPE cpe:2.3:a:langflow:langflow:1.4.2:-:*:*:*:*:*:*
First Time Langflow langflow
Langflow

23 Jan 2026, 04:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-23 04:16

Updated : 2026-06-17 10:11


NVD link : CVE-2026-0771

Mitre link : CVE-2026-0771

CVE.ORG link : CVE-2026-0771


JSON object : View

Products Affected

langflow

  • langflow
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')