---
id: GHSA-frvg-495w-m47v
title: >-
  Duplicate Advisory: Langflow: PythonREPLComponent executes unsandboxed Python
  code, enabling authenticated RCE and privilege escalation
summary: >-
  Duplicate Advisory: Langflow: PythonREPLComponent executes unsandboxed Python
  code, enabling authenticated RCE and privilege escalation
severity: critical
cvss: 10
cwe:
  - CWE-94
vendor: langlow
product: langlow
ecosystem: pip
affected:
  - langlow < 1.10.1
patched:
  - langlow 1.10.1
published: '2026-06-22'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T13:38:21Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-frvg-495w-m47v'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-10561'
  - url: 'https://www.ibm.com/support/pages/node/7277242'
  - url: 'https://github.com/advisories/GHSA-frvg-495w-m47v'
tags:
  - ghsa
  - pip
ingestedAt: '2026-10-06T14:00:19.136Z'
---

## Overview

## Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-8qpj-27x8-pwpq. This link is maintained to preserve external references.

## Original Description
IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arbitrary code on the host system, resulting in complete compromise

## Affected packages

- `langlow < 1.10.1`

## Remediation

Upgrade to a patched release:

- `langlow 1.10.1`
