{"id":"GHSA-8qpj-27x8-pwpq","summary":"Langflow: PythonREPLComponent executes unsandboxed Python code, enabling authenticated RCE and privilege escalation","details":"### Summary\n\nLangflow's built-in Python interpreter components — `PythonREPLComponent` (Python Interpreter) and the legacy `PythonREPLToolComponent` (Python REPL Tool) — executed arbitrary user- or model-supplied Python code inside flows without effective sandboxing. Because the code ran in-process with the privileges of the Langflow service, any **authenticated** user who could edit and run a flow could achieve remote code execution and, from there, escalate privileges to superuser (e.g. by opening a database session and flipping `is_superuser`) or compromise the host.\n\n**This issue is fixed as of 1.10.1**, with additional hardening through 1.12.3. See *Remediation* below.\n\n### Affected\n\n- **Package:** `langflow` (PyPI), and the underlying `lfx` package that ships the component.\n- **Vulnerable versions:** `\u003c 1.10.1`.\n- **Patched:** `1.10.1` (core fix). Upgrade to `\u003e= 1.12.3` for the complete hardening series.\n\n### Details\n\nThe root cause is **code injection** (CWE-94/CWE-95): the component passed raw input to LangChain's `PythonREPL`, which is explicitly *not* a security sandbox.\n\nTwo distinct weaknesses existed before 1.10.1:\n\n1. **Unrestricted builtins (default deployments).** `get_globals()` built the `exec` globals from the `global_imports` allow-list but never set `__builtins__`. CPython's `exec()` then auto-injected the full `builtins` module, leaving `__import__`, `open`, `eval`, `exec` and the whole import machinery reachable regardless of the allow-list — e.g. `__import__(\"os\").system(...)` or `__import__(\"subprocess\").check_output([...])`. This made the \"only modules in Global Imports can be used\" guarantee false, and it applied even with the **default** configuration (`allow_custom_components=True`).\n\n2. **No server-policy gate (locked-down deployments).** Even a deployment hardened with `allow_custom_components=False` could still run interpreter code, because the components did not consult that policy before executing.\n\nBoth let an authenticated user run the reported PoC, which opens a DB session and sets `is_superuser = True` on their account, or writes to the filesystem / runs OS commands with the service's privileges.\n\n### PoC (as reported)\n\n1. Authenticate as a normal user.\n2. Create a flow with the `PythonREPLComponent`.\n3. Execute Python that imports Langflow internals and elevates the account:\n\n```python\nimport asyncio\nfrom sqlmodel import select\nfrom langflow.services.database.models.user.model import User\nfrom langflow.services.deps import session_scope\n\nasync def escalate():\n    async with session_scope() as session:\n        stmt = select(User).where(User.username == 'testuser')\n        user = (await session.exec(stmt)).first()\n        if user:\n            user.is_superuser = True\n            session.add(user)\n            await session.commit()\n\nasyncio.run(escalate())\n```\n\n### Impact\n\nAny authenticated user could:\n- Execute arbitrary Python / OS commands with the Langflow service's privileges (RCE).\n- Escalate their own account to superuser via direct database access.\n- Read/modify data and configuration, and potentially pivot to the underlying host.\n\n### Remediation\n\nUpgrade to **Langflow 1.10.1 or later** (preferably **\u003e= 1.12.3**). The interpreter components were hardened with layered, defense-in-depth controls, applied in `run_python_repl()` before any code is executed:\n\n- **Restricted builtins** — `get_globals()` injects a curated `safe_builtins()` mapping, removing `__import__`, `eval`, `exec`, `compile`, `open`, `input`, `globals`/`locals`/`vars`, `getattr`/`setattr`, etc. (#13397)\n- **AST validation** — `validate_code_safety()` rejects inline `import`/`from ... import`, dunder/escape-gadget attribute access (`__class__`, `__subclasses__`, `__globals__`, frame/traceback introspection) and format-string dunder traversal. (#13397)\n- **Server-policy gate** — `ensure_code_execution_enabled()` refuses to run when `allow_custom_components=False` or `block_code_interpreter_components=True`, and **fails closed** if the settings stack cannot be resolved. (#13700 — this advisory — and #14375)\n- **Allow-listed module proxies** — imported modules are exposed via a proxy that blocks reaching `sys.modules[\"os\"]` through a module's transitive import graph. (#15198)\n- **Optional hardware isolation** — configure `LANGFLOW_SANDBOX_BACKEND` to run interpreter code in an isolated microVM instead of in-process. (#14400)\n\nUpstream fix references: #13397, #13700 (carries this GHSA), #14375, #14400, #15198.\n\n### Hardening recommendations for operators\n\n- Keep Langflow updated (\u003e= 1.12.3).\n- For locked-down deployments, set `LANGFLOW_ALLOW_CUSTOM_COMPONENTS=false` (or `LANGFLOW_BLOCK_CODE_INTERPRETER_COMPONENTS=true`) to disable the interpreter entirely.\n- For deployments that must run untrusted code, configure `LANGFLOW_SANDBOX_BACKEND` for microVM isolation.\n- Run the Langflow service as an unprivileged user with least-privilege database credentials.","aliases":["CVE-2026-10561"],"modified":"2026-10-06T13:45:05.689796501Z","published":"2026-10-06T13:38:28Z","database_specific":{"cwe_ids":["CWE-266","CWE-94","CWE-95"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2026-10-06T13:38:28Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/langflow-ai/langflow/security/advisories/GHSA-8qpj-27x8-pwpq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-10561"},{"type":"WEB","url":"https://github.com/langflow-ai/langflow/pull/13700"},{"type":"WEB","url":"https://github.com/langflow-ai/langflow/commit/2754c84aad1306f463db1c3bbb3e8ffbe85da77d"},{"type":"PACKAGE","url":"https://github.com/langflow-ai/langflow"},{"type":"WEB","url":"https://github.com/langflow-ai/langflow/releases/tag/v1.10.1"},{"type":"WEB","url":"https://www.ibm.com/support/pages/node/7277242"}],"affected":[{"package":{"name":"langflow","ecosystem":"PyPI","purl":"pkg:pypi/langflow"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.10.1"}]}],"versions":["0.0.31","0.0.32","0.0.33","0.0.40","0.0.44","0.0.45","0.0.46","0.0.52","0.0.53","0.0.54","0.0.55","0.0.56","0.0.57","0.0.58","0.0.61","0.0.62","0.0.63","0.0.64","0.0.65","0.0.66","0.0.67","0.0.68","0.0.69","0.0.70","0.0.71","0.0.72","0.0.73","0.0.74","0.0.75","0.0.76","0.0.78","0.0.79","0.0.80","0.0.81","0.0.83","0.0.84","0.0.85","0.0.86","0.0.87","0.0.88","0.0.89","0.1.0","0.1.2","0.1.3","0.1.4","0.1.5","0.1.6","0.1.7","0.2.0","0.2.1","0.2.10","0.2.11","0.2.12","0.2.13","0.2.2","0.2.3","0.2.4","0.2.5","0.2.6","0.2.7","0.2.8","0.2.9","0.3.0","0.3.1","0.3.2","0.3.3","0.3.4","0.4.0","0.4.1","0.4.10","0.4.11","0.4.12","0.4.14","0.4.15","0.4.16","0.4.17","0.4.18","0.4.19","0.4.2","0.4.20","0.4.21","0.4.3","0.4.4","0.4.5","0.4.6","0.4.7","0.4.8","0.4.9","0.5.0","0.5.0a0","0.5.0a1","0.5.0a2","0.5.0a3","0.5.0a4","0.5.0a5","0.5.0a6","0.5.0b0","0.5.0b2","0.5.0b3","0.5.0b4","0.5.0b5","0.5.0b6","0.5.1","0.5.10","0.5.11","0.5.12","0.5.2","0.5.3","0.5.4","0.5.5","0.5.6","0.5.7","0.5.8","0.5.9","0.6.0","0.6.0rc1","0.6.1","0.6.10","0.6.11","0.6.12","0.6.14","0.6.15","0.6.16","0.6.17","0.6.18","0.6.19","0.6.2","0.6.3","0.6.3a0","0.6.3a1","0.6.3a2","0.6.3a3","0.6.3a4","0.6.3a5","0.6.3a6","0.6.3a7","0.6.4","0.6.4a0","0.6.4a1","0.6.5","0.6.5a0","0.6.5a1","0.6.5a10","0.6.5a11","0.6.5a12","0.6.5a13","0.6.5a2","0.6.5a3","0.6.5a4","0.6.5a5","0.6.5a6","0.6.5a7","0.6.5a8","0.6.5a9","0.6.6","0.6.7","0.6.7a1","0.6.7a2","0.6.7a3","0.6.7a5","0.6.8","0.6.9","1.0.0","1.0.0a0","1.0.0a1","1.0.0a10","1.0.0a11","1.0.0a12","1.0.0a13","1.0.0a14","1.0.0a15","1.0.0a17","1.0.0a18","1.0.0a19","1.0.0a2","1.0.0a20","1.0.0a21","1.0.0a22","1.0.0a23","1.0.0a24","1.0.0a25","1.0.0a26","1.0.0a27","1.0.0a28","1.0.0a29","1.0.0a3","1.0.0a30","1.0.0a31","1.0.0a32","1.0.0a33","1.0.0a34","1.0.0a35","1.0.0a36","1.0.0a37","1.0.0a38","1.0.0a39","1.0.0a4","1.0.0a40","1.0.0a41","1.0.0a42","1.0.0a43","1.0.0a44","1.0.0a45","1.0.0a46","1.0.0a47","1.0.0a48","1.0.0a49","1.0.0a5","1.0.0a50","1.0.0a51","1.0.0a52","1.0.0a53","1.0.0a55","1.0.0a56","1.0.0a57","1.0.0a58","1.0.0a59","1.0.0a6","1.0.0a60","1.0.0a61","1.0.0a7","1.0.0a8","1.0.0a9","1.0.0rc0","1.0.0rc1","1.0.1","1.0.10","1.0.11","1.0.12","1.0.13","1.0.14","1.0.15","1.0.16","1.0.17","1.0.18","1.0.19","1.0.19.post1","1.0.19.post2","1.0.2","1.0.3","1.0.4","1.0.5","1.0.6","1.0.7","1.0.8","1.0.9","1.1.0","1.1.1","1.1.2","1.1.3","1.1.4","1.1.4.post1","1.10.0","1.10.0rc0","1.10.1rc0","1.10.1rc3","1.2.0","1.3.0","1.3.1","1.3.2","1.3.3","1.3.4","1.4.0","1.4.1","1.4.2","1.4.3","1.5.0","1.5.0.post1","1.5.0.post2","1.5.1","1.6.0","1.6.1","1.6.2","1.6.3","1.6.4","1.6.5","1.6.6","1.6.7","1.6.8","1.6.9","1.7.0","1.7.1","1.7.2","1.7.3","1.8.0","1.8.0rc0","1.8.0rc1","1.8.0rc2","1.8.0rc3","1.8.0rc4","1.8.0rc5","1.8.0rc6","1.8.1","1.8.2","1.8.3","1.8.3rc0","1.8.4","1.9.0","1.9.1","1.9.2","1.9.3","1.9.3rc0","1.9.4","1.9.5","1.9.6","1.9.6rc0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-8qpj-27x8-pwpq/GHSA-8qpj-27x8-pwpq.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"}]}