{"id":"CVE-2026-101861","title":"Langflow 1.0.16 before 1.12.0 and 0.0.94 before 1.12.0 contain an unsafe eval() vulnerability in schema.py that allows authenticated attackers to achieve code execution by placing a Python object with a malicious __repr__ method into com…","summary":"Langflow 1.0.16 before 1.12.0 and 0.0.94 before 1.12.0 contain an unsafe eval() vulnerability in schema.py that allows authenticated attackers to achieve code execution by placing a Python object with a malicious __repr__ method into com…","severity":"medium","cvss":4.1,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L","cwe":["CWE-94","CWE-95"],"vendor":"langflow-ai","product":"langflow","affected":["langflow >= 1.0.16 < 1.12.0","langflow >= 0.0.94 < 1.12.0"],"published":"2026-09-28","updated":"2026-09-28","sourceUpdated":"2026-09-28T16:17:13.157","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-101861","references":[{"url":"https://github.com/langflow-ai/langflow/releases#release-v1.12.0","label":"disclosure@vulncheck.com"},{"url":"https://github.com/langflow-ai/langflow/security/advisories/GHSA-33p4-w7j3-33mw","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-28T16:15:01.368Z","slug":"CVE-2026-101861","body":"## Overview\n\nLangflow 1.0.16 before 1.12.0 and 0.0.94 before 1.12.0 contain an unsafe eval() vulnerability in schema.py that allows authenticated attackers to achieve code execution by placing a Python object with a malicious __repr__ method into component input options lists. The eval() sink is triggered when a component is converted into a LangChain tool via ComponentToolkit.get_tools(), including during custom component saves through the API, by interpolating options into a Literal type string that is passed directly to eval() without safe evaluation controls.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":23,"depthScoreParts":{"impact":22.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}