Skip to content
LangflowGHSA-v8hw-mh8c-jxfc

Langflow has Authenticated Code Execution in Agentic Assistant Validation

CriticalCVE-2026-33873 · Published Mar 26, 2026 · updated Jun 6, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
langflow
PyPI
< 1.9.01.9.0
Details and references

## Description ### 1. Summary The Agentic Assistant feature in Langflow executes LLM-generated Python code during its **validation** phase. Although this phase appears intended to validate generated component code, the implementation reaches dynamic execution sinks and instantiates the generated class server-side. In deployments where an attacker can access the Agentic Assistant feature and influence the model output, this can result in arbitrary server-side Python execution. ### 2. Description #### 2.1 Intended Functionality The Agentic Assistant endpoints are designed to help users generate and validate components for a flow. Users can submit requests to the assistant, which returns candidate component code for further processing. A reasonable security expectation is that validation should treat model output as **untrusted text** and perform only static or side-effect-free checks. The externally reachable endpoints are: [https://github.com/langflow-ai/langflow/blob/f7f4d1e70ba5eecd18162ec96f3571c2cfbcd1fc/src/backend/base/langflow/agentic/api/router.py#L252-L297](https://github.com/langflow-ai/langflow/blob/f7f4d1e70ba5eecd18162ec96f3571c2cfbcd1fc/src/backend/base/langflow/agentic/api/router.py#L252-L297) The request model accepts attacker-influenceable fields such as `input_value`, `flow_id`, `provider`, `model_name`, `session_id`, and `max_retries`: [https://github.com/langflow-ai/langflow/blob/f7f4d1e70ba5eecd18162ec96f3571c2cfbcd1fc/src/backend/base/langflow/agentic/api/schemas.py#L20-L31](https://github.com/langflow-ai/langflow/blob/f7f4d1e70ba5eecd18162ec96f3571c2cfbcd1fc/src/backend/base/langflow/agentic/api/schemas.py#L20-L31) #### 2.2 Root Cause In the affected code path, Langflow processes model output through the following chain: `/assist` → `execute_flow_with_validation()` → `execute_flow_file()` → LLM returns component code → `extract_component_code()` → `validate_component_code()` → `create_class()` → generated class is instantiated The assistant service reaches the validation path here: [https://github.com/langflow-ai/langflow/blob/f7f4d1e70ba5eecd18162ec96f3571c2cfbcd1fc/src/backend/base/langflow/agentic/services/assistant_service.py#L58-L79](https://github.com/langflow-ai/langflow/blob/f7f4d1e70ba5eecd18162ec96f3571c2cfbcd1fc/src/backend/base/langflow/agentic/services/assistant_service.py#L58-L79) The code extraction step occurs here: [https://github.com/langflow-ai/langflow/blob/f7f4d1e70ba5eecd18162ec96f3571c2cfbcd1fc/src/backend/base/langflow/agentic/helpers/code_extraction.py#L11-L53](https://github.com/langflow-ai/langflow/blob/f7f4d1e70ba5eecd18162ec96f3571c2cfbcd1fc/src/backend/base/langflow/agentic/helpers/code_extraction.py#L11-L53) The validation entry point is here: [https://github.com/langflow-ai/langflow/blob/f7f4d1e70ba5eecd18162ec96f3571c2cfbcd1fc/src/backend/base/langflow/agentic/helpers/validation.py#L27-L47](https://github.com/langflow-ai/langflow/blob/f7f4d1e70ba5eecd18162ec96f3571c2cfbcd1fc/src/backend/base/langflow/agentic/helpers/validation.py#L27-L47) The issue is that this validation path is not purely static. It ultimately invokes `create_class()` in `lfx.custom.validate`, where Python code is dynamically executed via `exec(...)`, including both global-scope preparation and class construction. [https://github.com/langflow-ai/langflow/blob/f7f4d1e70ba5eecd18162ec96f3571c2cfbcd1fc/src/lfx/src/lfx/custom/validate.py#L241-L272](https://github.com/langflow-ai/langflow/blob/f7f4d1e70ba5eecd18162ec96f3571c2cfbcd1fc/src/lfx/src/lfx/custom/validate.py#L241-L272) [https://github.com/langflow-ai/langflow/blob/f7f4d1e70ba5eecd18162ec96f3571c2cfbcd1fc/src/lfx/src/lfx/custom/validate.py#L394-L399](https://github.com/langflow-ai/langflow/blob/f7f4d1e70ba5eecd18162ec96f3571c2cfbcd1fc/src/lfx/src/lfx/custom/validate.py#L394-L399) [https://github.com/langflow-ai/langflow/blob/f7f4d1e70ba5eecd18162ec96f3571c2cfbcd1fc/src/lfx/src/lfx/custom/validate.py#L441-L443](https://github.c

CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-94
Also known as
CVE-2026-33873, PYSEC-2026-82

More Langflow advisories

All Langflow
DateAdvisory
Mar 27Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check
CVE-2026-34046Highfixed in 1.5.1
Mar 20langflow: /profile_pictures/{folder_name}/{file_name} endpoint file reading
CVE-2026-33497Highfixed in 1.7.1
Mar 20langflow has Unauthenticated IDOR on Image Downloads
CVE-2026-33484High7.5fixed in 1.9.0
Mar 19Langflow has an Arbitrary File Write (RCE) via v2 API
CVE-2026-33309Critical9.9fixed in 1.9.0
Mar 18Langflow is Missing Ownership Verification in API Key Deletion (IDOR)
CVE-2026-33053Highfixed in 1.9.0
Mar 17Unauthenticated Remote Code Execution in Langflow via Public Flow Build Endpoint
CVE-2026-33017Critical9.8fixed in 1.9.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.