Threat intelligence, Threat Research

IBM Langflow OSS unauthenticated RCE

by Dhiren Vaghela

IBM Langflow OSS
Unauthenticated RCE (CVE-2026-9198)

OVERVIEW

The SonicWall Capture Labs threat research team became aware of an Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation in Langflow AI, assessed its impact and developed mitigation measures. Langflow AI is a Python-based web application that provides a visual interface to build AI-driven agents and workflows.

The issue, tracked as CVE-2026-9198, affects versions 1.0.0 through 1.10.0 and has been added to the CISA-KEV catalog. This flaw, categorized under CWE-94 (Improper Control of Generation of Code (Code Injection)), allows an unauthenticated remote attacker to achieve remote code execution, earning a critical CVSS score of 9.8. Langflow processes user-controlled JSON data and passes Python code embedded in node definitions directly to Python's exec() function, without sandboxing. When the application handles component node configurations or code validation sequences, it processes user-controlled parameters and routes the embedded custom Python code strings straight into Python's native exec() processing function without using an isolated or restricted sandbox environment. As Langflow continues to gain popularity and broader adoption, the risk associated with this vulnerability increases significantly. Users are strongly encouraged to apply the vendor-provided updates without delay.

TECHNICAL OVERVIEW

Langflow offers a visual interface that makes it easy to design workflows, along with built-in APIs and MCP servers that allow these workflows to be used as tools in applications across different frameworks and technologies. It comes with many built-in features and supports major LLMs, vector databases, and a growing set of AI tools.

Figure 1 illustrates the overall Langflow architecture. Users can visually build workflows, which are sent to the backend API server for management and execution. The execution engine processes the flow step by step, invoking AI models, tools, and external services as needed, and then returns the results while storing data in databases or file storage.

Figure_1_Langflow_Architecture.JPG
Figure 1: Langflow Architecture

Key security characteristics of Langflow include:

  • Its modular flow-based architecture.
  • Support for integration with external services such as LLMs and APIs.
  • The ability to execute dynamically defined workflows.
  • In patched versions, Langflow enforces stricter trust boundaries by ensuring that only validated, server-side flow definitions are executed, thereby reducing the risk of code injection and unauthorized manipulation.
ROOT CAUSE

The vulnerability stems from the lack of input validation and sandboxing when Langflow handles code validation and custom node verification components.

Specifically, the flaw is a two-part failure chain:

  • Unsafe Code Execution (CWE-94): The application relies on Python's built-in exec() function to process custom script logic submitted within component configurations. Because the string is evaluated raw inside the host operating system's process context, any embedded system-level commands run with the full permissions of the web server application.
  • Authentication Bypass Deployment (Default Behavior): In affected versions, the administrative backend leaves the automatic session route (/api/v1/auto_login) active by default, allowing external network connections to mint a valid SUPERUSER web token without providing username or password credentials, rendering the dangerous execution endpoint completely exposed to the network.
PATCH ANALYSIS

The security fix introduced in version 1.10.1, as shown in Figures 2 and 3, involves two specific logic routing files mapping to critical endpoints. The remediation patch implemented in Langflow v1.10.1 introduces structural validation changes to both logic nodes:

File 1: Authentication Router (src/backend/langflow/api/v1/login.py)

This file controls the handling of automatic logins. In default deployments, AUTO_LOGIN permitted instant token generation for any network request without enforcing an identity or localhost constraint.

Figure_2_Patch_diff_of_login.py.jpg
Figure 2: Patch diff of login.py

File 2: Validate Router (src/backend/langflow/api/v1/validate.py)

This file evaluates custom workflows and user-submitted scripts. The vulnerable code parsed structural properties at runtime using standard string evaluations via exec(), enabling attackers to trick the parser into executing OS commands.

Figure_3_Patch_diff_of_validate.py.png
Figure 3: Patch diff of validate.py

Furthermore, in v1.10.1, the 365-day no-refresh superuser token is replaced with normally scoped create_user_tokens() (a short-lived access token and a refresh token), as shown in api_v1_login.diff in Figure 4.

Figure_4_Patched_api_v1_login.diff.jpg
Figure 4: Patched api_v1_login.diff

TRIGGERING THE VULNERABILITY

The exploitation process typically follows these steps:

  1. The attacker targets the vulnerable endpoint to collect access tokens by sending a simple GET request to auto_login: http://<target-ip>:7860/api/v1/auto_login
  2. Plain GET with no Authorization header and no request body, answered 200 with a JSON access_token. Any 200 here means the instance mints superuser tokens to anyone.
  3. The JWT's decoded expiry is ~365 days out — a bearer token with a year-long lifetime is itself an anomaly worth alerting on.
  4. The environment variable LANGFLOW_AUTO_LOGIN=True is a prerequisite.
  5. After bypassing authentication and obtaining the superuser JWT access token, the attacker sends a POST request to /api/v1/validate/code — protected only by that token, the endpoint passes the request body to lfx.custom.validate.validate_code(), which compile()s and exec()s every top-level function definition.
  6. This code is passed to exec() with zero sandboxing, resulting in unauthenticated remote code execution.

EXPLOITATION

Successful exploitation enables a remote, unauthenticated attacker to steal an authentication token and use it to gain full control of the affected system. Figure 5 demonstrates a real-world proof of concept, showing successful token capture and RCE achieved as uid=1000(user) — the account running Langflow — giving full control of the application, its SQLite database, stored API keys and global variables, using a publicly available exploit. Given Langflow’s extensive system privileges, this vulnerability can result in complete compromise of the operator’s machine.

Figure_5_Exploit_in_Action.gif
Figure 5: Exploit in Action

SONICWALL PROTECTIONS

To ensure SonicWall customers are prepared for any exploitation that may occur due to this vulnerability, the following signatures have been released:

  • IPS: 20973 Langflow AI Remote Code Execution 2
  • IPS: 22481 Langflow AI Remote Code Execution 3

REMEDIATION RECOMMENDATIONS

With Langflow’s growing user base and increasing deployment footprint, organizations and individual users should upgrade to the latest patched version as outlined in the official vendor advisory.

RELEVANT LINKS

Share This Article

An Article By

Dhiren Vaghela

Senior Software Development Engineer

Dhiren Vaghela has over a decade of experience in the IPS domain, with a strong focus on defensive security. His expertise lies in identifying, analyzing and mitigating vulnerabilities. Dhiren is well-versed in content-based signature writing, scanner-based alert generation and technical blog writing. By leveraging emerging technologies, he has developed numerous IPS signatures across various protocols. Known for his exceptional signature writing skills and collaborative team spirit, Dhiren is a valuable asset in the field of cybersecurity.

Related Articles

  • Oracle HTTP & WebLogic Servers Proxy Plug-in Authentication Bypass
    Read More
  • Langflow AI Untrusted Control Sphere Remote Code Execution
    Read More