Langflow: Title Authenticated Remote Code Execution in validate_code via Malicious Decorators Description
High8.8CVE-2026-51886 · Published Oct 5, 2026
###Summary: A critical Authenticated Remote Code Execution (RCE) vulnerability exists in the validate_code function of Langflow. The` /api/v1/validate/code` endpoint, meant to validate user-supplied code, leverages Python's exec() function. While it attempts to restrict execution to function definitions, it fails to account for decorators, which are evaluated at definition time. This allows any authenticated user to execute arbitrary code on the server, resulting in a full system compromise. ### Details The vulnerability is located in `src/lfx/src/lfx/custom/validate.py(exposed via src/backend/base/langflow/api/v1/validate.py`). The validate_code function parses user input using ast. When it encounters a FunctionDef node, it compiles and executes it to check for extensive errors: ``` # src/lfx/src/lfx/custom/validate.py if isinstance(node, ast.FunctionDef): code_obj = compile(ast.Module(body=[node], type_ignores=[]), "<string>", "exec") # ... # exec_globals creates a restricted-looking scope, but standard builtins are available exec(code_obj, exec_globals) ``` By design, executing a function definition (def func(): ...) does not execute the function body. How...
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| langflow PyPI | >= 1.7.2, < 1.10.1 | 1.10.1 |
Details and references
###Summary: A critical Authenticated Remote Code Execution (RCE) vulnerability exists in the validate_code function of Langflow. The` /api/v1/validate/code` endpoint, meant to validate user-supplied code, leverages Python's exec() function. While it attempts to restrict execution to function definitions, it fails to account for decorators, which are evaluated at definition time. This allows any authenticated user to execute arbitrary code on the server, resulting in a full system compromise. ### Details The vulnerability is located in `src/lfx/src/lfx/custom/validate.py(exposed via src/backend/base/langflow/api/v1/validate.py`). The validate_code function parses user input using ast. When it encounters a FunctionDef node, it compiles and executes it to check for extensive errors: ``` # src/lfx/src/lfx/custom/validate.py if isinstance(node, ast.FunctionDef): code_obj = compile(ast.Module(body=[node], type_ignores=[]), "<string>", "exec") # ... # exec_globals creates a restricted-looking scope, but standard builtins are available exec(code_obj, exec_globals) ``` By design, executing a function definition (def func(): ...) does not execute the function body. However, Python immediately evaluates decorators attached to the function definition. An attacker can supply a malicious decorator (e.g., a lambda or function call) to achieve immediate code execution during the "validation" phase. ### Affected Versions - **`/api/v1/validate/code` had no authentication at all** until commit `3fed9fe1b5` ("fix: Add authentication to various endpoints", #10977), first released in **v1.7.2**. Before that release, this same `exec()` sink was reachable **unauthenticated**. - From **v1.7.2 through v1.10.0**, the endpoint required a valid session but the `exec()` sink was untouched, so any authenticated user (or any user at all under `AUTO_LOGIN`) could trigger RCE via a malicious decorator as described below. - Fixed in **v1.10.1** , see Fix section. ### PoC - Authenticate as any user (acquire a valid access token or API key). - Send a POST request to /api/v1/validate/code with the following JSON payload: ``` { "code": "@lambda x: (__import__('os').system('touch /tmp/pwned'), x)[1]\ndef pwned():\n pass" } ``` Curl Example ``` curl -X POST "http://<TARGET_HOST>/api/v1/validate/code" \ -H "Authorization: Bearer <YOUR_TOKEN>" \ -H "Content-Type: application/json" \ -d '{"code": "@lambda x: (__import__(\"os\").system(\"echo RCE_SUCCESS > /tmp/pwned\"), x)[1]\ndef pwned():\n pass"}' ``` Verify: Check the server file system. The file /tmp/pwned will be created. ### Impact This vulnerability results in Remote Code Execution (RCE). Impacted Parties: Any user with access to the Langflow instance (Authenticated Users). Consequence: An attacker can execute arbitrary commands with the privileges of the process running Langflow. This allows reading sensitive environment variables (API keys, DB credentials), modifying files, or launching further attacks on the internal network. ### Fix Fixed in **v1.10.1** by PR [#13696](https://github.com/langflow-ai/langflow/pull/13696) (commit `e7c33dbaad`, tracked as **GHSA-2wcq-pvw2-xh7v**): `validate_code()` in `src/lfx/src/lfx/custom/validate.py` no longer `exec()`s submitted `FunctionDef` nodes. It now only `compile()`s them to surface syntax/compile errors, which never evaluates decorators or default-argument expressions, closing this sink entirely. This same fix independently resolves the different exploitation technique reported in duplicate advisory **GHSA-xjq8-cqrm-7m4x** (RCE via default-argument evaluation instead of a decorator). Both advisories share the exact same root-cause sink , the unconditional `exec()` in `validate_code()` , and differ only in which Python construct (decorator vs. default argument) is used to trigger execution at definition time. Credit for this finding is accordingly shared with the reporter of that duplicate.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-94
- Also known as
- CVE-2026-51886
- github.com/langflow-ai/langflow/security/advisories/GHSA-w584-2h2r-2hvf
- nvd.nist.gov/vuln/detail/CVE-2026-51886
- github.com/langflow-ai/langflow/issues/13336
- github.com/langflow-ai/langflow/pull/13696
- github.com/langflow-ai/langflow/commit/e7c33dbaade20b5295c7fa26bf83cc1ff68fba02
- gist.github.com/Ro1ME/c11b1e63e4e8fca6b25275144f25ec2a
- github.com/langflow-ai/langflow
- github.com/langflow-ai/langflow/releases/tag/v1.10.1
More Langflow advisories
All Langflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 5 | Langflow: Weak Fernet Key via random.seed() | Critical9.1 | 1.10.1 |
| Oct 5 | Langflow: Unauthenticated Flow Execution via Webhook Authentication Bypass | Critical9.8 | 1.9.1 |
| Oct 5 | Langflow: Prompt injection in Langflow Smart Transform can lead to code execution | High8.8 | 1.10.3 |
| Jun 19 | Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit | Critical9.6 | 1.9.2 |
| Jun 19 | Langflow: Unauthenticated DoS through multipart form boundary file upload | High7.5 | 1.0.19 |
| Jun 19 | Langflow: Logout button does not clear session | Medium6.1 | 1.7.0 |