Advisories

Langflow Code Execution via eval() in Component Input Schema

Go Back
severity
low
date
Affecting
  • langflow >= 1.0.16, < 1.12.0

  • langflow >= 0.0.94, < 1.12.0

CWE
  • CWE-95 Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
  • CWE-94 Improper Control of Generation of Code ('Code Injection')
CVSS
2.1
CVSS V4 Vector
CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Credit
Weblover
Description
Langflow 1.0.16 before 1.12.0 and 0.0.94 before 1.12.0 contain an unsafe eval() vulnerability in schema.py that allows authenticated attackers to achieve code execution by placing a Python object with a malicious __repr__ method into component input options lists. The eval() sink is triggered when a component is converted into a LangChain tool via ComponentToolkit.get_tools(), including during custom component saves through the API, by interpolating options into a Literal type string that is passed directly to eval() without safe evaluation controls.

Ready to get Started?

Explore VulnCheck, a next-generation Cyber Threat Intelligence platform, which provides exploit and vulnerability intelligence to help you prioritize and remediate vulnerabilities that matter.
  • Vulnerability Prioritization
    Prioritize vulnerabilities that matter based on the threat landscape and defer vulnerabilities that don't.
  • Early Warning System
    Real-time alerting of changes in the vulnerability landscape so that you can take action before the attacks start.