logo

Langflow CSV Agent Flaw Could Let Attackers Execute Arbitrary Code

ID: b6997cd6-ff64-5847-a92e-d44e404fe0c1

STIX ID: report--b6997cd6-ff64-5847-a92e-d44e404fe0c1

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-03-02

Date Updated: 2026-04-22

Author: Divya

...
...

**Executive summary:** A critical RCE vulnerability (CVE-2026-27966) in Langflow's CSV Agent arises from a hardcoded allow_dangerous_code=True which auto-enables LangChain's Python REPL; a PoC shows attackers can run arbitrary OS commands, and users are urged to update to version 1.8.0 or disable code-execution features.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.