CVE-2026-27966·Python vulnerability
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.8.0, the CSV Agent node in Langflow hardcodes `allow_dangerous_code=True`, which automatically exposes LangChain’s Python REPL tool (`python_repl_ast`). As a result, an attacker can execute arbitrary Python and OS commands on the server via prompt injection, leading to full Remote Code Execution (RCE). Version 1.8.0 fixes the issue.
- Severity
- critical
- Software
- Python
- Fixed in
- 1.8.0
- Published
- 2026-02-26
Affected versions
Until: 1.8.0
Fixed in: 1.8.0
How to fix this CVE
Upgrade Langflow to version 1.8.0 or later to disable the dangerous code execution setting in the CSV Agent node. This patch removes the hardcoded `allow_dangerous_code=True` parameter that was exposing Python REPL functionality to prompt injection attacks. Organizations running earlier versions should prioritize this update to prevent remote code execution through malicious CSV inputs or agent prompts.
sudo dnf update python3-langflowDefensia detects this vulnerability
WAF mitigation (if patching is not yet possible)
Add this rule to your WAF to block exploitation attempts while you schedule the patch.
Implement input validation rules that block or sanitize CSV uploads and prompt inputs containing Python keywords (`exec`, `eval`, `__import__`, `os.system`, `subprocess`). Add rate limiting on Langflow API endpoints that process CSV Agent requests to slow down reconnaissance and exploitation attempts.How to check if you are affected
- Run `pip show langflow | grep Version` to check the installed Langflow version; versions below 1.8.0 are vulnerable
- Inspect your Langflow workflow configuration files (typically in ~/.langflow or /opt/langflow) for CSV Agent nodes; check if they contain `allow_dangerous_code: true` in the node definition
- Search application logs for patterns like `python_repl_ast` or `exec()` calls originating from CSV Agent processing to identify exploitation attempts
- After upgrading, re-run `pip show langflow | grep Version` and confirm the version is 1.8.0 or higher, then restart the Langflow service
FAQ
What is CVE-2026-27966?
CVE-2026-27966 is a critical remote code execution vulnerability in Langflow versions prior to 1.8.0 where the CSV Agent node unconditionally enables dangerous code execution, allowing attackers to inject malicious Python commands through prompts or CSV data that get executed on the server.
Is CVE-2026-27966 being actively exploited?
No, this vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities (KEV) catalog, and no public exploits have been disclosed. However, given the critical CVSS score of 9.8, immediate patching is strongly recommended.
What versions of Langflow are affected by CVE-2026-27966?
All versions of Langflow prior to 1.8.0 are affected. Version 1.8.0 and later include the fix that disables the dangerous code execution setting by default.
How do I check if my server is vulnerable to CVE-2026-27966?
Run `pip show langflow | grep Version` and compare the output against 1.8.0; if your version is lower, your installation is vulnerable. You can also check for the presence of CSV Agent nodes in active workflows using `grep -r 'allow_dangerous_code' ~/.langflow/`.
Does Defensia detect CVE-2026-27966?
Yes — Defensia's CVE advisory scanner compares installed Langflow package versions against the NVD database. If Langflow is installed on a monitored server, CVE-2026-27966 will appear in your dashboard with remediation steps and affected version details.
Related Python CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-27966. Free for 1 server.
Get started free