GHSA-w584-2h2r-2hvf: Code Injection

Published Oct 5, 2026
·
Updated

###Summary: A critical Authenticated Remote Code Execution (RCE) vulnerability exists in the validatecode function of Langflow. The /api/v1/validate/code endpoint, meant to validate user-supplied code, leverages Python's exec() function. While it attempts to restrict execution to function definitions, it fails to account for decorators, which are evaluated at definition time. This allows any authenticated user to execute arbitrary code on the server, resulting in a full system compromise.

Details The vulnerability is located in src/lfx/src/lfx/custom/validate.py(exposed via src/backend/base/langflow/api/v1/validate.py).

The validatecode function parses user input using ast. When it encounters a FunctionDef node, it compiles and executes it to check for extensive errors:

src/lfx/src/lfx/custom/validate.py if isinstance(node, ast.FunctionDef): codeobj = compile(ast.Module(body=[node], typeignores=[]), "<string>", "exec") # ... # execglobals creates a restricted-looking scope, but standard builtins are available exec(codeobj, execglobals)

By design, executing a function definition (def func(): ...) does not execute the function body. However, Python immediately evaluates decorators attached to the function definition. An attacker can supply a malicious decorator (e.g., a lambda or function call) to achieve immediate code execution during the "validation" phase.

Affected Versions

- /api/v1/validate/code had no authentication at all until commit 3fed9fe1b5 ("fix: Add authentication to various endpoints", #10977), first released in v1.7.2. Before that release, this same exec() sink was reachable unauthenticated. - From v1.7.2 through v1.10.0, the endpoint required a valid session but the exec() sink was untouched, so any authenticated user (or any user at all under AUTOLOGIN) could trigger RCE via a malicious decorator as described below. - Fixed in v1.10.1 — see Fix section.

PoC - Authenticate as any user (acquire a valid access token or API key). - Send a POST request to /api/v1/validate/code with the following JSON payload: { "code": "@lambda x: (import('os').system('touch /tmp/pwned'), x)[1]\ndef pwned():\n pass" } Curl Example curl -X POST "http://<TARGETHOST>/api/v1/validate/code" \ -H "Authorization: Bearer <YOURTOKEN>" \ -H "Content-Type: application/json" \ -d '{"code": "@lambda x: (import(\"os\").system(\"echo RCESUCCESS > /tmp/pwned\"), x)[1]\ndef pwned():\n pass"}' Verify: Check the server file system. The file /tmp/pwned will be created.

Impact This vulnerability results in Remote Code Execution (RCE).

Impacted Parties: Any user with access to the Langflow instance (Authenticated Users). Consequence: An attacker can execute arbitrary commands with the privileges of the process running Langflow. This allows reading sensitive environment variables (API keys, DB credentials), modifying files, or launching further attacks on the internal network.

Fix Fixed in v1.10.1 by PR #13696 (commit e7c33dbaad, tracked as GHSA-2wcq-pvw2-xh7v): validatecode() in src/lfx/src/lfx/custom/validate.py no longer exec()s submitted FunctionDef nodes. It now only compile()s them to surface syntax/compile errors, which never evaluates decorators or default-argument expressions, closing this sink entirely.

This same fix independently resolves the different exploitation technique reported in duplicate advisory GHSA-xjq8-cqrm-7m4x (RCE via default-argument evaluation instead of a decorator). Both advisories share the exact same root-cause sink — the unconditional exec() in validatecode() — and differ only in which Python construct (decorator vs. default argument) is used to trigger execution at definition time. Credit for this finding is accordingly shared with the reporter of that duplicate.

Affected Software

1 affected componentFixes available
pip/langflow>=1.7.2<1.10.1
1.10.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade pip/langflow to a version that resolves this vulnerability.

    Fixed in 1.10.1
  2. Upgrade

    Upgrade Langflow to a version that resolves this vulnerability.

    Fixed in v1.10.1Patch GHSA-2wcq-pvw2-xh7v

Event History

Oct 5, 2026
Advisory Published
via GitHub·10:31 PM
Data Sourced
via GitHub·10:31 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What level of access does an attacker need?

An attacker needs an authenticated Langflow account. No user interaction is required after authentication.

2

What can a successful attacker do?

The attacker can execute arbitrary code on the Langflow server through the code-validation endpoint. The advisory describes the resulting impact as full system compromise, including high confidentiality, integrity, and availability impact.

3

Which interface is involved in exploitation?

Exploitation targets the /api/v1/validate/code endpoint. The vulnerable validation path executes submitted Python function definitions, and decorators can run code when those definitions are processed.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203