highCVSS 8.8Vulnerability

CVE-2026-7700

## Summary Langflow versions 1.3.0 through 1.10.2 contain a code-injection vulnerability in the Smart Transform (`LambdaFilterComponent`) component. Smart Transform places flow-author instructions and a preview of its input data into a prompt asking an LLM to generate a Python lambda. It then extracts a one-line lambda from the model response, applies only syntactic format checks, evaluates it with Python's full builtins, and invokes the resulting function inside the Langflow process. A malicious flow author can exploit this directly through the Instructions field. In deployments where an exposed flow passes attacker-controlled content into Smart Transform, an attacker may also exploit it indirectly through prompt injection, subject to the configured model following the injected instruction. ## Vulnerability details **Vulnerable Code Location**: `src/lfx/src/lfx/components/llm_operations/lambda_filter.py` (line 242 in v1.10.2) ```python def _validate_lambda(self, lambda_text: str) -> bool: """Validate the provided lambda function text.""" return lambda_text.strip().startswith("lambda") and ":" in lambda_text # ... return eval(lambda_text) # noqa: S307 ``` For example, an attacker can attempt to make the model return: `lambda x: __import__("os").system("id")` This expression satisfies the vulnerable format checks. `eval()` creates the lambda with access to Python's default builtins, and the subsequent `fn(data)` invocation (in `_execute_lambda`) executes the command. Successful exploitation allows code execution with the privileges of the Langflow service process. This can expose or modify credentials, files, application data, and network resources accessible to that process, and may affect other tenants in shared deployments. ## PoC https://github.com/user-attachments/assets/13c48fe1-7225-4e0d-9687-2d2df1e87f0e ## Fix The reported path was addressed by validating the generated code's AST and evaluating it with a restricted builtins mapping.

Properties

severity
high
summary
Langflow: Prompt injection in Langflow Smart Transform can lead to code execution
epss_score
0.00393
cvss_score
8.8
retrieved_at
2026-10-05T22:59:58+00:00
ghsa_published
2026-10-05T22:30:41Z
source_url
https://github.com/advisories/GHSA-9fpm-3445-2vx4
ghsa_updated
2026-10-05T22:30:42Z
ghsa_id
GHSA-9fpm-3445-2vx4
last_source
FIRST EPSS
cve_id
CVE-2026-7700
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
signal_observed_at
2026-10-05T22:52:21+00:00
is_ghsa_only
false
epss_percentile
0.31087

Related Entities (5)

ENRICHED_BY (1)

→[Source]FIRST EPSS

VULNERABLE_TO (1)

←[Software]pip/langflow

AFFECTS (1)

→[Software]pip/langflow

HAS_WEAKNESS (1)

→[Weakness]Improper Control of Generation of Code ('Code Injection')

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-7700 (CVSS 8.8) — Ninja Signal Threat Intelligence | Ninja Signal