CVE-2026-27966

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.8.0, the CSV Agent node in Langflow hardcodes `allow_dangerous_code=True`, which automatically exposes LangChain’s Python REPL tool (`python_repl_ast`). As a result, an attacker can execute arbitrary Python and OS commands on the server via prompt injection, leading to full Remote Code Execution (RCE). Version 1.8.0 fixes the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*

History

28 Feb 2026, 00:54

Type Values Removed Values Added
References () https://github.com/langflow-ai/langflow/commit/d8c6480daa17b2f2af0b5470cdf5c3d28dc9e508 - () https://github.com/langflow-ai/langflow/commit/d8c6480daa17b2f2af0b5470cdf5c3d28dc9e508 - Patch
References () https://github.com/langflow-ai/langflow/security/advisories/GHSA-3645-fxcv-hqr4 - () https://github.com/langflow-ai/langflow/security/advisories/GHSA-3645-fxcv-hqr4 - Exploit, Vendor Advisory
First Time Langflow langflow
Langflow
CPE cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*

27 Feb 2026, 15:16

Type Values Removed Values Added
References () https://github.com/langflow-ai/langflow/security/advisories/GHSA-3645-fxcv-hqr4 - () https://github.com/langflow-ai/langflow/security/advisories/GHSA-3645-fxcv-hqr4 -

27 Feb 2026, 14:06

Type Values Removed Values Added
Summary
  • (es) Langflow es una herramienta para construir y desplegar agentes y flujos de trabajo impulsados por IA. Antes de la versión 1.8.0, el nodo CSV Agent en Langflow codifica de forma rígida 'allow_dangerous_code=True', lo que expone automáticamente la herramienta Python REPL de LangChain ('python_repl_ast'). Como resultado, un atacante puede ejecutar comandos arbitrarios de Python y del sistema operativo en el servidor a través de inyección de prompts, lo que lleva a una ejecución remota de código (RCE) completa. La versión 1.8.0 soluciona el problema.

26 Feb 2026, 15:17

Type Values Removed Values Added
References () https://github.com/langflow-ai/langflow/security/advisories/GHSA-3645-fxcv-hqr4 - () https://github.com/langflow-ai/langflow/security/advisories/GHSA-3645-fxcv-hqr4 -

26 Feb 2026, 02:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-26 02:16

Updated : 2026-02-28 00:54


NVD link : CVE-2026-27966

Mitre link : CVE-2026-27966

CVE.ORG link : CVE-2026-27966


JSON object : View

Products Affected

langflow

  • langflow
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')