Langflow CSV Agent node RCE via prompt injection (CVE-2026-27966)
Langflow versions prior to 1.8.0 hardcoded `allow_dangerous_code=True` in the CSV Agent node, exposing LangChain's Python REPL tool so an attacker could run arbitrary Python and OS commands on the server via prompt injection. Version 1.8.0 fixes the issue.
Disclosed 26 February 2026 · Record updated 13 September 2026
Impact
Full remote code execution on servers running affected Langflow versions via prompt injection into the CSV Agent node.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-27966
