Vulnerability PYSEC-2026-1525

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
2 months ago
July 07, 2026 at 04:03 PM UTC
Langflow affected by Remote Code Execution via validate_code() exec()
0.0.31 - 1.7.3
0.0.31 - 1.7.3

Summary

Langflow affected by Remote Code Execution via validate_code() exec()

Details

Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the handling of the exec_globals parameter provided to the validate endpoint. The issue results from the inclusion of a resource from an untrusted control sphere. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-27325.

Impacted packages

Timeline

Published
2 months ago
July 07, 2026 at 04:03 PM UTC
Last Modified
2 months ago
July 07, 2026 at 05:46 PM UTC