CVE-2026-27966 - Vulnerability Analysis
CriticalCVSS: 9.8Last Updated: February 26, 2026
Langflow - Remote Code Execution
Published: February 26, 2026Updated: February 26, 2026Remote Exploitable
Overview
Langflow < 1.8.0 contains a remote code execution caused by hardcoded allow_dangerous_code=True exposing LangChain's python_repl_ast tool, letting attackers execute arbitrary Python and OS commands via prompt injection.
Severity & Score
Severity: Critical
CVSS Score: 9.8
Impact
Attackers can execute arbitrary Python and OS commands on the server, leading to full remote code execution and system compromise.
Mitigation
Update to version 1.8.0 or later.
References
Related Resources
Details
- CVE ID
- CVE-2026-27966
- Severity
- Critical
- CVSS Score
- 9.8
- Type
- remote_code_execution
- Status
- new
CWE
- CWE-94
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H