CVE-2026-27966Disclosure(langflow / langflow)

HIGHCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 6 mentions and remains active

Immediate actions

  • Patch langflow langflow systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: Immediate (within 24h)

NVD description

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.8.0, the CSV Agent node in Langflow hardcodes `allow_dangerous_code=True`, which automatically exposes LangChain’s Python REPL tool (`python_repl_ast`). As a result, an attacker can execute arbitrary Python and OS commands on the server via prompt injection, leading to full Remote Code Execution (RCE). Version 1.8.0 fixes the issue.

6.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • langflow

Threat summary

  • Active exploitation appears in 2 classified signals
  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 17 mentions across 7 observed days

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 14 signals
  • Disclosure: 7 classified signals
  • General: 2 classified signals
  • Peaked 6d ago at 6 mentions (2026-02-26); latest day: 1
  • 17 total mentions across 7 days

Affected systems

Vendors
Products
langflow

Deep dive

Activity timeline17 mentions / 7d
02356Mentions · 2026-02-26: 6Mentions · 2026-03-02: 5Mentions · 2026-03-03: 1Mentions · 2026-03-04: 2Mentions · 2026-03-09: 1Mentions · 2026-03-27: 1Mentions · 2026-04-24: 1Exploit Tool / Code · 2026-04-24: 1Active Exploitation · 2026-03-02: 1Active Exploitation · 2026-03-27: 1Patch / Workaround · 2026-02-26: 2Patch / Workaround · 2026-03-02: 2Patch / Workaround · 2026-03-09: 1Technical Details · 2026-02-26: 5Technical Details · 2026-03-02: 5Technical Details · 2026-03-03: 1Technical Details · 2026-03-04: 1Technical Details · 2026-03-09: 1Technical Details · 2026-03-27: 102-2603-0203-0303-0403-0903-2704-24
Signal classification5 categories
Disclosure
741.2%
Patch
529.4%
General
211.8%
Active Exploitation
211.8%
Exploit
15.9%
Referenced assets17 URLs
Classification over time
DateTotalLabels
2026-02-266
Disclosure3General1Patch2
2026-03-025
Active Exploitation1Disclosure2Patch2
2026-03-031
Disclosure1
2026-03-042
Disclosure1General1
2026-03-091
Patch1
2026-03-271
Active Exploitation1
2026-04-241
Exploit1
Full discourse17 posts
  • ZoomEye@zoomeye_team
    Disclosure

    🔥 CVE-2026-27966: Vulnerability Alert Critical Remote Code Execution via Unsafe LLM Chain Deserialization! Attackers supply a maliciously crafted YAML payload in Langflow's chain configuration import endpoint, exploiting unsafe deserialization of untrusted input to execute arbitrary Python code on the server. Full Vulnerability Details & Analysis at DarkEye: 🔗 https://darkeye.org/vuln/cve/CVE-2026-27966 🔍 Identify Targets via ZoomEye: Filter: vul.cve="CVE-2026-27966" Search Dork: app="Langflow" Exposure: 3k+ instances identified globally. ZoomEye Search Link: 👉 https://www.zoomeye.ai/searchResult?q=YXBwPSJMYW5nZmxvdyI=&utm_source=twitter&utm_medium=social&utm_campaign=cve_ops_20260302 #RCE #Deserialization #Langflow #LLMSecurity #BugBounty #DarkEye

    Post summary

    CVE-2026-27966 is a critical remote code execution vulnerability in Langflow caused by unsafe deserialization of YAML payloads, allowing attackers to execute arbitrary Python code via the chain configuration import endpoint.

    1802553.9K
    11.9K followersView on X
  • Metasploit Project@metasploit
    Exploit

    The latest Metasploit Weekly Wrapup is here! Highlights include a new RCE exploit for Langflow (CVE-2026-27966), improved check method visibility with detailed reasoning, and updates for legacy SMB targets. Plus 3 other new modules! Read more: https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-04-25-2026/

    Post summary

    Rapid7 announced a new Metasploit module that exploits RCE in Langflow (CVE-2026-27966), extending the tool’s attack surface.

    1502062.7K
    253.4K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Langflow 1.8.0 patches a critical 9.8 CVSS RCE vulnerability (CVE-2026-27966) where a hardcoded "allow_dangerous_code" setting enables prompt injection attacks. #Langflow #AISecurity #CyberSecurity #RCE #InfoSec #PromptInjection #LLM #Vulnerability https://securityonline.info/critical-9-8-flaw-in-langflows-ai-csv-agent-opens-a-direct-path-to-root-shell/

    Post summary

    Langflow released version 1.8.0 to patch a critical 9.8‑scored RCE vulnerability (CVE‑2026‑27966) where a hard‑coded allow_dangerous_code setting enabled prompt injection attacks.

    12021605
    10.5K followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL RCE in langflow-ai langflow (<1.8.0)! Unauthenticated attackers can run arbitrary Python & OS commands via prompt injection. Patch ASAP to avoid full system compromise. https://radar.offseq.com/threat/cve-2026-27966-cwe-94-improper-control-of-generati-8ac7c0b0 #OffS... https://t.co/RT2WP7XEr1

    Post summary

    A critical RCE in langflow-ai langflow (<1.8.0) allows unauthenticated attackers to execute arbitrary Python and OS commands via prompt injection; patch immediately to prevent system compromise.

    0001284
    270 followersView on X
  • DarkEye@darkeye_team
    Active Exploitation

    🚨 Detailed Analysis for CVE-2026-27966 (Vulnerability Alert) Stop guessing the risk. The technical details are ready. 🔥 $5 Special Trial to celebrate our CVE Feed launch! Get the Analysis & Prioritized Asset List now: 🔗 https://www.darkeye.org/vuln/cve/CVE-2026-27966 Critical Unauthenticated Remote Code Execution! Attackers exploit a deserialization flaw in Langflow's flow import endpoint to execute arbitrary code without authentication by submitting malicious YAML payloads. cc: @zoomeye_team (3k+ targets detected 🎯) #CVE202627966 #Langflow #RCE #DarkEye #zoomeye_team #BugBounty

    Post summary

    The post announces CVE‑2026‑27966, describing a remote code execution flaw via malicious YAML, and alleges that attackers are actively exploiting it, with no PoC, patch, or debunking information provided.

    00020216
    960 followersView on X
  • にゃん☆たく/takumi.a@taku888infinity
    Disclosure

    【セキュリティ ニュース】「Langflow」にプロンプトインジェクションによるRCE脆弱性(1ページ目 / 全1ページ):Security NEXT https://www.security-next.com/181562 『プロンプトインジェクションによりリモートより任意のコードを実行される脆弱性「CVE-2026-27966」が確認された。「CSV Agent」コンポーネントの初期化において危険なコードを許可する設定となっており、「LangChain」における「Python REPLツール」が自動的に有効となり、外部へ公開されている状態だった。』

    Post summary

    A newly disclosed prompt‑injection vulnerability (CVE‑2026‑27966) in Langflow permits remote code execution via the CSV Agent component and an exposed Python REPL tool; no PoC, exploit, patch, or active exploitation is reported.

    000111.5K
    11.3K followersView on X
  • iototsecnews@iototsecnews
    Patch

    Langflow CSV Agent の脆弱性 CVE-2026-27966 が FIX:プロンプト・インジェクションによる RCE https://iototsecnews.jp/2026/03/02/langflow-csv-agent-flaw-could-let-attackers-execute-arbitrary-code/ 今回の Langflow における深刻な脆弱性 CVE-2026-27966 は、CSV Agent の仕組みに起因しています。具体的には、プログラム内でコード実行を許可する設定が、意図せずに常に有効化されており、攻撃者が悪意の命令を送り込むことで、サーバ上での任意の操作が可能になっていました。この設定を無効化する手段がないことから、利用者が気づかないうちに危険に晒される状態でした。開発環境であっても、こうした安全機能の設定が固定されているとリスクが高まります。バージョン 1.8.0 への更新をお急ぎください。 #CSVAgent #CVE202627966 #Langflow #Vulnerability

    Post summary

    Langflow CSV Agent CVE-2026-27966 exposes a prompt‑injection flaw that allows arbitrary code execution; the issue is fixed in update 1.8.0 and users are urged to upgrade immediately.

    01000142
    484 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers are exploiting CVE-2026-27966 in Langflow's CSV Agent node to execute arbitrary Python commands without authentication. The hardcoded `allow_dangerous_code=True` parameter exposes LangChain's Python REPL tool for remote code execution. Runtime segmentation helps limit blast radius when AI development platforms are compromised. #ZeroDay #CloudSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/langflow-2026-cve-2026-27966-code-injection

    Post summary

    The post confirms that CVE‑2026‑27966 in Langflow’s CSV Agent node is actively exploited, enabling unauthenticated remote code execution via a hardcoded parameter, with no patches or PoC code detailed here.

    0000055
    1.9K followersView on X
  • セキュリティ対策Lab@securityLab_jp
    General

    鹿児島県立短期大学、教員メールアカウントで迷惑メール 大量送信-メールアカウントへの不正アクセスか https://rocket-boys.co.jp/security-measures-lab/langflow-csv-agent-unauthenticated-rce-cve-2026-27966-2/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    The post references a CVE and a potential spam incident but offers no technical, exploit, or mitigation details.

    00000169
    324 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Disclosure

    LangflowのCSV Agentに未認証RCEの重大な脆弱性(CVE-2026-27966) https://rocket-boys.co.jp/security-measures-lab/langflow-csv-agent-unauthenticated-rce-cve-2026-27966/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    A new un‑authenticated RCE vulnerability (CVE‑2026‑27966) in Langflow’s CSV Agent has been disclosed.

    0000097
    324 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-27966 (CVSS:9.8, CRITICAL) is Analyzed. Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.8.0, the CSV Agent nod..https://nvd.nist.gov/vuln/detail/CVE-2026-27966 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces a critical vulnerability (CVE-2026-27966) in Langflow’s CSV Agent before version 1.8.0, noting its CVSS score and linking to the NVD entry.

    0000030
    173 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Langflow “CSV Agent” prompt-injection flaw enables remote code execution on AI workflow servers (CVE-2026-27966) Langflow versions <1.8.0 hardcode `allow_dangerous_code=True` in the CSV Agent node, exposing LangChain’s Python REPL tool so an attacker can use prompt injection to run arbitrary Python/OS commands and fully compromise the server. Upgrade to Langflow 1.8.0+ and restrict/disable the CSV Agent node in untrusted deployments. 🎯 Target: Global/AI Dev Tools (Langflow deployments) #️⃣ Category: #Vulnerability #AI_Threats 🔗 URL: https://cyberpress.org/langflow-ai-csv-agent-flaw/

    Post summary

    Langflow’s CSV Agent node contains a prompt‑injection flaw that enables remote code execution; users should upgrade to version 1.8.0+ or disable the node to mitigate the risk.

    0000066
    244 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27966 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.8.0, the CSV Agent node in Langflow hardcodes `allow_dangerous_code=… https://www.cve.org/CVERecord?id=CVE-2026-27966

    Post summary

    A CVE (CVE-2026-27966) affecting Langflow's CSV Agent node due to a hardcoded `allow_dangerous_code` flag is disclosed, but no PoC, exploit, or patch details are provided.

    00000104
    56.6K followersView on X
  • المتفائل@MLTxc1YJNFAGW49
    General

    @langflow_ai @getpostman @SonicDMG @gethackteam @RubenCasas CVE-2026-27966 Has it been processed?

    Post summary

    The tweet merely asks whether CVE-2026-27966 has been processed, providing no additional details.

    0000071
    117 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27966 Remote Code Execution in Langflow CSV Agent via Prompt Injection Before 1.8.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27966

    Post summary

    A new CVE (CVE-2026-27966) has been disclosed, describing a remote code execution vulnerability in Langflow CSV Agent via prompt injection in versions prior to 1.8.0.

    0000072
    4.0K followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-27966** pertains to a critical security flaw in **Langflow**, an open-source tool used for building and deploying AI-powered agents and workflows. The vulnerability exists in versions prior to **1.8.0**, specifically within the **CSV Agent node**. Due to a hardcoded parameter `allow_dangerous_code=True`, the system inadvertently exposes the **Python REPL** (`python_repl_ast`) to prompt injection attacks. #Cybersecurity #CVE #CriticalCVE #CriticalVulnerability #RemoteCodeExecution https://cvetodo.com/cve/CVE-2026-27966

    Post summary

    The post announces CVE-2026-27966, a critical flaw in Langflow’s CSV Agent node that allows prompt injection via a hardcoded dangerous code flag, but does not provide PoC, exploit, or patch information.

    0000057
    20 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-27966: CRITICAL] Warning: Langflow version 1.8.0 fixes a critical security vulnerability allowing Remote Code Execution via the CSV Agent node. Update your software to stay protected.#cve,CVE-2026-27966,#cybersecurity https://cvefind.com/CVE-2026-27966

    Post summary

    Langflow 1.8.0 patch addresses CVE-2026-27966, a critical RCE via the CSV Agent node; updating mitigates the risk.

    0000068
    585 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applangflowlangflow---

Explore more