Langflow CSV Agent Flaw Could Let Attackers Execute Arbitrary Code
ID: b6997cd6-ff64-5847-a92e-d44e404fe0c1
STIX ID: report--b6997cd6-ff64-5847-a92e-d44e404fe0c1
Feed Name: GBHackers
Threat Score
**Executive summary:** A critical RCE vulnerability (CVE-2026-27966) in Langflow's CSV Agent arises from a hardcoded allow_dangerous_code=True which auto-enables LangChain's Python REPL; a PoC shows attackers can run arbitrary OS commands, and users are urged to update to version 1.8.0 or disable code-execution features.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
