CVE-2026-101861: Langflow-Ai Langflow

Medium severity, CVSS 4.1. EPSS: 0.2% chance of exploitation in the next 30 days.

Langflow 1.0.16 before 1.12.0 and 0.0.94 before 1.12.0 contain an unsafe eval() vulnerability in schema.py that allows authenticated attackers to achieve code execution by placing a Python object with a malicious __repr__ method into component input options lists. The eval() sink is triggered when a component is converted into a LangChain tool via ComponentToolkit.get_tools(), including during custom component saves through the API, by interpolating options into a Literal type string that is passed directly to eval() without safe evaluation controls.

Affected products

  • Langflow-Ai Langflow: from 1.0.16, before 1.12.0 (fixed in 1.12.0); from 0.0.94, before 1.12.0 (fixed in 1.12.0)

Published 2026-09-28. Last modified 2026-09-30.