VDB
Sign up
—

PYSEC-2026-380

Langflow Unauth RCE

Quick fix

PYSEC-2026-380 — langflow-base: upgrade to the fixed version with the command below.

pip install --upgrade 'langflow-base>=0.3.0'

Details

Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/langflow-base
Introduced in: 0Fixed in: 0.3.0
Fixpip install --upgrade 'langflow-base>=0.3.0'

References