
The SonicWall Capture Labs threat research team became aware of an Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation in Langflow AI, assessed its impact and developed mitigation measures. Langflow AI is a Python-based web application that provides a visual interface to build AI-driven agents and workflows.
The issue, tracked as CVE-2026-9198, affects versions 1.0.0 through 1.10.0 and has been added to the CISA-KEV catalog. This flaw, categorized under CWE-94 (Improper Control of Generation of Code (Code Injection)), allows an unauthenticated remote attacker to achieve remote code execution, earning a critical CVSS score of 9.8. Langflow processes user-controlled JSON data and passes Python code embedded in node definitions directly to Python's exec() function, without sandboxing. When the application handles component node configurations or code validation sequences, it processes user-controlled parameters and routes the embedded custom Python code strings straight into Python's native exec() processing function without using an isolated or restricted sandbox environment. As Langflow continues to gain popularity and broader adoption, the risk associated with this vulnerability increases significantly. Users are strongly encouraged to apply the vendor-provided updates without delay.
Langflow offers a visual interface that makes it easy to design workflows, along with built-in APIs and MCP servers that allow these workflows to be used as tools in applications across different frameworks and technologies. It comes with many built-in features and supports major LLMs, vector databases, and a growing set of AI tools.
Figure 1 illustrates the overall Langflow architecture. Users can visually build workflows, which are sent to the backend API server for management and execution. The execution engine processes the flow step by step, invoking AI models, tools, and external services as needed, and then returns the results while storing data in databases or file storage.
Key security characteristics of Langflow include:
The vulnerability stems from the lack of input validation and sandboxing when Langflow handles code validation and custom node verification components.
Specifically, the flaw is a two-part failure chain:
The security fix introduced in version 1.10.1, as shown in Figures 2 and 3, involves two specific logic routing files mapping to critical endpoints. The remediation patch implemented in Langflow v1.10.1 introduces structural validation changes to both logic nodes:
File 1: Authentication Router (src/backend/langflow/api/v1/login.py)
This file controls the handling of automatic logins. In default deployments, AUTO_LOGIN permitted instant token generation for any network request without enforcing an identity or localhost constraint.

File 2: Validate Router (src/backend/langflow/api/v1/validate.py)
This file evaluates custom workflows and user-submitted scripts. The vulnerable code parsed structural properties at runtime using standard string evaluations via exec(), enabling attackers to trick the parser into executing OS commands.

Furthermore, in v1.10.1, the 365-day no-refresh superuser token is replaced with normally scoped create_user_tokens() (a short-lived access token and a refresh token), as shown in api_v1_login.diff in Figure 4.

The exploitation process typically follows these steps:
Successful exploitation enables a remote, unauthenticated attacker to steal an authentication token and use it to gain full control of the affected system. Figure 5 demonstrates a real-world proof of concept, showing successful token capture and RCE achieved as uid=1000(user) — the account running Langflow — giving full control of the application, its SQLite database, stored API keys and global variables, using a publicly available exploit. Given Langflow’s extensive system privileges, this vulnerability can result in complete compromise of the operator’s machine.

To ensure SonicWall customers are prepared for any exploitation that may occur due to this vulnerability, the following signatures have been released:
With Langflow’s growing user base and increasing deployment footprint, organizations and individual users should upgrade to the latest patched version as outlined in the official vendor advisory.
Share This Article

An Article By
An Article By
Dhiren Vaghela
Dhiren Vaghela
Dhiren Vaghela has over a decade of experience in the IPS domain, with a strong focus on defensive security. His expertise lies in identifying, analyzing and mitigating vulnerabilities. Dhiren is well-versed in content-based signature writing, scanner-based alert generation and technical blog writing. By leveraging emerging technologies, he has developed numerous IPS signatures across various protocols. Known for his exceptional signature writing skills and collaborative team spirit, Dhiren is a valuable asset in the field of cybersecurity.