{"id":"CVE-2026-101861","published":"2026-09-28T16:17:13.157","lastModified":"2026-09-28T16:17:13.157","description":"Langflow 1.0.16 before 1.12.0 and 0.0.94 before 1.12.0 contain an unsafe eval() vulnerability in schema.py that allows authenticated attackers to achieve code execution by placing a Python object with a malicious __repr__ method into component input options lists. The eval() sink is triggered when a component is converted into a LangChain tool via ComponentToolkit.get_tools(), including during custom component saves through the API, by interpolating options into a Literal type string that is passed directly to eval() without safe evaluation controls.","cvssScore":4.1,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L","cwes":["CWE-94","CWE-95"],"vendors":[],"products":[],"references":[{"url":"https://github.com/langflow-ai/langflow/releases#release-v1.12.0","tags":[]},{"url":"https://github.com/langflow-ai/langflow/security/advisories/GHSA-33p4-w7j3-33mw","tags":[]}],"exploitRefs":[{"url":"https://github.com/langflow-ai/langflow/releases#release-v1.12.0","tags":[]},{"url":"https://github.com/langflow-ai/langflow/security/advisories/GHSA-33p4-w7j3-33mw","tags":[]}],"hasPoc":true,"ai":null}