critical CVSS 9.8

CVE-2026-27966·Python vulnerability

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.8.0, the CSV Agent node in Langflow hardcodes `allow_dangerous_code=True`, which automatically exposes LangChain’s Python REPL tool (`python_repl_ast`). As a result, an attacker can execute arbitrary Python and OS commands on the server via prompt injection, leading to full Remote Code Execution (RCE). Version 1.8.0 fixes the issue.

Severity
critical
Software
Python
Fixed in
1.8.0
Published
2026-02-26

Affected versions

Until: 1.8.0

Fixed in: 1.8.0

How to fix this CVE

Upgrade Langflow to version 1.8.0 or later to disable the dangerous code execution setting in the CSV Agent node. This patch removes the hardcoded `allow_dangerous_code=True` parameter that was exposing Python REPL functionality to prompt injection attacks. Organizations running earlier versions should prioritize this update to prevent remote code execution through malicious CSV inputs or agent prompts.

sudo dnf update python3-langflow

Defensia detects this vulnerability

WAF mitigation (if patching is not yet possible)

Add this rule to your WAF to block exploitation attempts while you schedule the patch.

Implement input validation rules that block or sanitize CSV uploads and prompt inputs containing Python keywords (`exec`, `eval`, `__import__`, `os.system`, `subprocess`). Add rate limiting on Langflow API endpoints that process CSV Agent requests to slow down reconnaissance and exploitation attempts.

How to check if you are affected

  1. Run `pip show langflow | grep Version` to check the installed Langflow version; versions below 1.8.0 are vulnerable
  2. Inspect your Langflow workflow configuration files (typically in ~/.langflow or /opt/langflow) for CSV Agent nodes; check if they contain `allow_dangerous_code: true` in the node definition
  3. Search application logs for patterns like `python_repl_ast` or `exec()` calls originating from CSV Agent processing to identify exploitation attempts
  4. After upgrading, re-run `pip show langflow | grep Version` and confirm the version is 1.8.0 or higher, then restart the Langflow service

FAQ

What is CVE-2026-27966?

CVE-2026-27966 is a critical remote code execution vulnerability in Langflow versions prior to 1.8.0 where the CSV Agent node unconditionally enables dangerous code execution, allowing attackers to inject malicious Python commands through prompts or CSV data that get executed on the server.

Is CVE-2026-27966 being actively exploited?

No, this vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities (KEV) catalog, and no public exploits have been disclosed. However, given the critical CVSS score of 9.8, immediate patching is strongly recommended.

What versions of Langflow are affected by CVE-2026-27966?

All versions of Langflow prior to 1.8.0 are affected. Version 1.8.0 and later include the fix that disables the dangerous code execution setting by default.

How do I check if my server is vulnerable to CVE-2026-27966?

Run `pip show langflow | grep Version` and compare the output against 1.8.0; if your version is lower, your installation is vulnerable. You can also check for the presence of CSV Agent nodes in active workflows using `grep -r 'allow_dangerous_code' ~/.langflow/`.

Does Defensia detect CVE-2026-27966?

Yes — Defensia's CVE advisory scanner compares installed Langflow package versions against the NVD database. If Langflow is installed on a monitored server, CVE-2026-27966 will appear in your dashboard with remediation steps and affected version details.

Related Python CVEs

CVE-2026-33054CVSS 10Mesop is a Python-based UI framework that allows users to build web applications. Versions 1.2.2 and below contain a Path Traversal vulnerability that allows any user supplying an untrusted state_token through the UI stream payload to arbitrarily target files on the disk under the standard file-based runtime backend. This can result in application denial of service (via crash loops when reading non-msgpack target files as configurations), or arbitrary file manipulation. This vulnerability heavily exposes systems hosted utilizing FileStateSessionBackend. Unauthorized malicious actors could interact with arbitrary payloads overwriting or explicitly removing underlying service resources natively outside the application bounds. This issue has been fixed in version 1.2.3.
CVE-2026-25632CVSS 10EPyT-Flow is a Python package designed for the easy generation of hydraulic and water quality scenario data of water distribution networks. Prior to 0.16.1, EPyT-Flow’s REST API parses attacker-controlled JSON request bodies using a custom deserializer (my_load_from_json) that supports a type field. When type is present, the deserializer dynamically imports an attacker-specified module/class and instantiates it with attacker-supplied arguments. This allows invoking dangerous classes such as subprocess.Popen, which can lead to OS command execution during JSON parsing. This also affects the loading of JSON files. This vulnerability is fixed in 0.16.1.
CVE-2026-34938CVSS 10PraisonAI is a multi-agent teams system. Prior to version 1.5.90, execute_code() in praisonai-agents runs attacker-controlled Python inside a three-layer sandbox that can be fully bypassed by passing a str subclass with an overridden startswith() method to the _safe_getattr wrapper, achieving arbitrary OS command execution on the host. This issue has been patched in version 1.5.90.
CVE-2026-28505CVSS 10Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the str_eval() function in notification_handler.py implements a sandboxed eval() for notification text templates. The sandbox attempts to restrict callable names by inspecting code.co_names of the compiled code object. However, co_names only contains names from the outer code object. When a lambda expression is used, it creates a nested code object whose attribute accesses are stored in code.co_consts, NOT in code.co_names. The sandbox never inspects nested code objects. This issue has been patched in version 2.17.0.
CVE-2026-9135CVSS 9.9IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulnerability in the Policies component's ToolGuard integration that bypasses the allow_custom_components=false security control. The vulnerability exists because the validation mechanism only checks the main component source code in node_template["code"]["value"] but fails to validate dynamic CodeInput fields that store generated ToolGuard Python files. Attackers can embed malicious Python code in these unvalidated dynamic fields, which are persisted in Flow.data and later executed server-side when a guarded tool is invoked through the ToolGuard runtime. This allows authenticated users with flow creation privileges to achieve arbitrary Python code execution on the backend despite custom component restrictions. The vulnerability can be escalated through cross-tenant flow manipulation via the agentic MCP update_flow_component_field tool, which accepts attacker-controlled user_id parameters, enabling attackers to inject malicious code into victim users' flows. When combined with publicly accessible flows and specific misconfigurations (AUTO_LOGIN=true, NEW_USER_IS_ACTIVE=true), the attack can be conducted with reduced authentication requirements.

References

Track CVEs across your fleet automatically

Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-27966. Free for 1 server.

Get started free