Critical Unauthenticated RCE in Langflow OSS PythonREPLComponent
IBM disclosed CVE-2026-10561, a critical unauthenticated remote code execution flaw in Langflow OSS affecting versions 1.0.0 through 1.9.3. The vulnerability is rooted in improper isolation in the PythonREPLComponent: CPython's exec() restores full builtins access when the globals dictionary does not explicitly clear __builtins__, allowing attackers to bypass the intended import restrictions. IBM and downstream advisories rate the issue CVSS 3.1 10.0, noting it is remotely exploitable with low attack complexity, requires no privileges, and needs no user interaction.
The flaw can be chained with Langflow's default LANGFLOW_AUTO_LOGIN=true behavior, which exposes the /api/v1/auto_login endpoint and can issue a superuser JWT without credentials, enabling unauthenticated code execution on the host. Successful exploitation could lead to arbitrary OS command execution, theft of LLM provider keys, flow definitions and vector store credentials, and persistent compromise of affected systems. IBM recommends upgrading to Langflow OSS 1.9.4 immediately; no workaround was listed, and defenders are advised to apply vendor updates, harden access controls, and monitor for unauthorized activity.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
1 event from the most recent confirmed update back to the earliest known activity.
IBM discloses CVE-2026-10561 in Langflow OSS
IBM published a security bulletin describing CVE-2026-10561, a critical unauthenticated remote code execution vulnerability affecting Langflow OSS versions 1.0.0 through 1.9.3. The bulletin says the flaw combines PythonREPLComponent builtins injection with Langflow's default auto-login behavior and recommends upgrading to version 1.9.4.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
2 references tracked. Mallory keeps watching after this page renders.
CVE-2026-10561 - Unauthenticated Remote Code Execution in Langflow OSS PythonREPLComponent via Builtins Injection
cvefeed.io
Open sourceSecurity Bulletin: Unauthenticated Remote Code Execution in Langflow OSS PythonREPLComponent via Builtins Injection
ibm.com
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


