logo

Critical 9.8 Flaw in Langflow’s AI CSV Agent Opens a Direct Path to Root Shell

ID: 61ce0b56-807f-5176-a940-894fd334706b

STIX ID: report--61ce0b56-807f-5176-a940-894fd334706b

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-03-02

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical RCE (CVE-2026-27966, CVSS 9.8) was disclosed in Langflow: the CSV Agent had a hardcoded backend setting (allow_dangerous_code=True) that enabled python_repl_ast, allowing attackers to use prompt-injection payloads to execute arbitrary system commands on the server. Administrators are urged to upgrade vulnerable deployments (versions prior to 1.6.9) to a secure release (recommended 1.8.0) to mitigate complete server takeover.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.