| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-9fpm-3445-2vx4 | Langflow: Prompt injection in Langflow Smart Transform can lead to code execution |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 06 Oct 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in langflow-ai langflow up to 1.8.4. This affects the function eval of the file src/lfx/src/lfx/components/llm_operations/lambda_filter.p of the component LambdaFilterComponent. Executing a manipulation can lead to code injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. | A weakness has been identified in langflow-ai langflow up to 1.10.2. This affects the function eval of the file src/lfx/src/lfx/components/llm_operations/lambda_filter.py of the component LambdaFilterComponent. Executing a manipulation can lead to code injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. |
| Title | langflow-ai langflow LambdaFilterComponent lambda_filter.p eval code injection | langflow-ai langflow LambdaFilterComponent lambda_filter.py eval code injection |
| References |
|
Tue, 05 May 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 03 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in langflow-ai langflow up to 1.8.4. This affects the function eval of the file src/lfx/src/lfx/components/llm_operations/lambda_filter.p of the component LambdaFilterComponent. Executing a manipulation can lead to code injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | langflow-ai langflow LambdaFilterComponent lambda_filter.p eval code injection | |
| First Time appeared |
Langflow
Langflow langflow |
|
| Weaknesses | CWE-74 CWE-94 |
|
| CPEs | cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Langflow
Langflow langflow |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-10-06T05:35:31.424Z
Reserved: 2026-05-02T20:24:22.085Z
Link: CVE-2026-7700
Updated: 2026-05-05T00:43:27.414Z
Status : Deferred
Published: 2026-05-03T15:15:59.693
Modified: 2026-10-06T06:17:01.897
Link: CVE-2026-7700
No data.
OpenCVE Enrichment
Updated: 2026-10-06T07:00:14Z
Github GHSA