PT-2026-36690 · Langflow · Langflow
Limshow
·
Published
2026-05-03
·
Updated
2026-05-03
·
CVE-2026-7687
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
langflow versions prior to 1.8.5
Description
A command injection issue exists in the Full Builtins Module Handler component. The flaw is located in the
parse callable details() function within the src/lfx/src/lfx/custom/code parser/code parser.py file. A remote attacker can execute a manipulation to perform command injection, which allows the execution of arbitrary system commands on the host operating system.Recommendations
Update to version 1.8.5 or later.
As a temporary workaround, restrict access to the
parse callable details() function until the update is applied.Exploit
Fix
Command Injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Langflow