LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-27966

CVE-2026-27966 - Vulnerability Analysis

CriticalCVSS: 9.8

Last Updated: February 26, 2026

Langflow - Remote Code Execution

Published: February 26, 2026Updated: February 26, 2026Remote Exploitable

Overview

Langflow < 1.8.0 contains a remote code execution caused by hardcoded allow_dangerous_code=True exposing LangChain's python_repl_ast tool, letting attackers execute arbitrary Python and OS commands via prompt injection.

Severity & Score

Severity: Critical
CVSS Score: 9.8

Impact

Attackers can execute arbitrary Python and OS commands on the server, leading to full remote code execution and system compromise.

Mitigation

Update to version 1.8.0 or later.

Details

CVE ID
CVE-2026-27966
Severity
Critical
CVSS Score
9.8
Type
remote_code_execution
Status
new

CWE

  • CWE-94

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H