Database/AI/ML frameworks & serving
Langflow: authenticated user reaches eval() through component input options and runs code on the host
Impact
Langflow builds a Literal type string by interpolating a component's input option values and passes it straight to eval(), so an object whose __repr__ returns attacker-chosen Python executes when the component is turned into a LangChain tool - including on an ordinary custom-component save through the API. On a GPU fleet Langflow usually runs as a long-lived pod next to the models it orchestrates and holds the credentials for them, so code execution there means the model endpoints, API keys and any mounted model storage that pod can reach. The record rates the required privilege as high, so this is an escalation from a trusted Langflow user to code on the serving host rather than an unauthenticated path.
Who can reach it
A user already authenticated to Langflow with permission to create or save custom components, over the network. No node-level access is needed.
What to do
Upgrade Langflow to 1.12.0 or later and restart the Langflow deployment; no node drain or reboot. Where an upgrade has to wait, restrict who can author or save custom components and treat the Langflow pod's service account and model credentials as exposed if untrusted users had that permission.
References
Related entries
- mistral.rs: out-of-bounds read parsing GGUF token id metadata crashes the inference serverCVE-2026-75090 · mistral.rs GGUF tokenizer (convert_gguf_to_hf_tokenizer)Low
- Ollama: integer overflow in the GGUF v1 string reader when parsing a crafted model fileCVE-2026-86289 · Ollama GGUF decoder (readGGUFV1String in fs/ggml/gguf.go)Low
- vLLM: attacker-supplied chat_template burns server resources on the GPU nodeCVE-2026-90878 · vLLM OpenAI-compatible server (/v1/chat/completions Jinja chat_template rendering)Low
- vLLM: malformed tiktoken vocab file crashes the tokenizer backend, denying service on the GPU nodeCVE-2026-90713 · vLLM (Rust tiktoken vocab file handler, TiktokenTokenizer::new)Low
- LangChain4j agentic: unsafe Jackson default typing in AgenticScope deserialization allows arbitrary class instantiationCVE-2026-97869 · LangChain4j agentic module (AgenticScopeSerializer JSON deserialization)Low
- llama.cpp: a crafted GGUF file trips a reachable assertion and aborts the process loading itCVE-2026-52131 · llama.cpp (gguf_reader::read GGUF model file parser)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.