← Blog · · df00tech

Langflow PythonREPLComponent Flaw Enables Authenticated RCE and Privilege Escalation (CVE-2026-10561)

breaking ghsa pip CVE-2026-10561

What happened

A GitHub Security Advisory (GHSA-8qpj-27x8-pwpq, CVE-2026-10561, CVSS 9.9) discloses that Langflow's built-in Python interpreter components — PythonREPLComponent and the legacy PythonREPLToolComponent — executed user- or model-supplied Python code without effective sandboxing. According to the advisory, this stemmed from two distinct issues in versions prior to 1.10.1: get_globals() never set __builtins__ when building the exec environment, so CPython auto-injected the full builtins module (including __import__, eval, exec, and open) regardless of the configured import allow-list; and the components did not consult the server's allow_custom_components policy before running, so even locked-down deployments remained exposed. A public proof-of-concept is reported: an authenticated user runs Python that opens a direct database session via Langflow's internal models and flips their own account's is_superuser flag to true.

Why it matters

Per the advisory, any authenticated user able to create and run a flow could achieve remote code execution with the privileges of the Langflow service, escalate to superuser via direct database manipulation, read or modify data and configuration, and potentially pivot to the underlying host. This is a code-injection flaw (CWE-94/95), not a sandbox-escape bug per se — the advisory is explicit that LangChain's PythonREPL, which the component wraps, was never designed as a security boundary. Organizations running multi-tenant or shared Langflow instances with any non-trusted authenticated users are most exposed.

What defenders should watch for

  • Inventory Langflow deployments and check version — the advisory marks everything below 1.10.1 vulnerable, with full hardening only landing by 1.12.3.
  • Review authentication/authorization logs for unexpected privilege changes on user accounts, particularly any user account that transitions to superuser outside of normal admin workflows.
  • Audit flow definitions for use of the Python Interpreter / Python REPL Tool components, especially flows created or edited by lower-privileged users.
  • If upgrading isn't immediately possible, the advisory recommends disabling the interpreter via LANGFLOW_ALLOW_CUSTOM_COMPONENTS=false or LANGFLOW_BLOCK_CODE_INTERPRETER_COMPONENTS=true, running the service as an unprivileged, least-privilege account, and — where untrusted code must run — isolating execution with LANGFLOW_SANDBOX_BACKEND microVM isolation.
  • Prioritize patching to Langflow >= 1.12.3, which the advisory says adds AST-based code validation, restricted builtins, a fail-closed server-policy gate, and allow-listed module proxies on top of the core 1.10.1 fix.

Developing intel

This is a same-day GHSA disclosure (published 2026-10-06) with a public PoC and no CVE exploitation-in-the-wild data yet reported; details may evolve as the community tests the patched hardening series. Full technical detail, affected version ranges, and remediation guidance are in the original advisory: GHSA-8qpj-27x8-pwpq.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.