{"id":"GHSA-qqw9-2vj9-hx7r","summary":"Duplicate Advisory: Title Authenticated Remote Code Execution in validate_code via Malicious Decorators Description","details":"## Duplicate Advisory\n\nThis advisory has been withdrawn because it is a duplicate of GHSA-w584-2h2r-2hvf. This link is maintained to preserve external references.\n\n## Original Description\nlangflow-ai langflow v1.9.3 is affected by: Code Injection. The impact is: execute arbitrary code (remote). The component is: src/backend/base/langflow/api/v1/validate.py:validate-post_validate_code-a-real-authenticated-http-post-to-api-v1. The attack vector is: Attack surface: HTTP or browser-backed service path. A public-facing route accepts raw Python source and forwards it into a server-side compile/exec validation path without any visible entitlement guard. ¶¶ A weakness has been identified in langflow-ai langflow up to 1.9.3. langflow contains a code injection vulnerability in validate-post_validate_code-a-real-authenticated-http-post-to-api-v1 (src/backend/base/langflow/api/v1/validate.py:13). An authenticated attacker can execute arbitrary Python code on the server by submitting malicious code to the /api/v1/validate/code endpoint, which directly executes user-supplied code without sandboxing or security controls.","modified":"2026-10-05T22:45:04.582824310Z","published":"2026-10-02T00:31:30Z","withdrawn":"2026-10-05T22:30:52Z","database_specific":{"cwe_ids":[],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-10-05T22:30:52Z","nvd_published_at":"2026-10-01T22:17:03Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-51886"},{"type":"WEB","url":"https://github.com/langflow-ai/langflow/issues/13336"},{"type":"WEB","url":"https://gist.github.com/Ro1ME/c11b1e63e4e8fca6b25275144f25ec2a"}],"affected":[{"package":{"name":"langflow","ecosystem":"PyPI","purl":"pkg:pypi/langflow"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.7.2"}]}],"versions":["1.10.0","1.10.0rc0","1.10.1","1.10.1rc0","1.10.1rc3","1.10.2","1.10.2rc4","1.10.3","1.10.3rc0","1.11.0","1.11.0.dev0","1.11.0.dev1","1.11.0.dev10","1.11.0.dev11","1.11.0.dev12","1.11.0.dev13","1.11.0.dev14","1.11.0.dev15","1.11.0.dev16","1.11.0.dev17","1.11.0.dev18","1.11.0.dev19","1.11.0.dev2","1.11.0.dev20","1.11.0.dev21","1.11.0.dev22","1.11.0.dev23","1.11.0.dev24","1.11.0.dev25","1.11.0.dev26","1.11.0.dev27","1.11.0.dev28","1.11.0.dev29","1.11.0.dev3","1.11.0.dev30","1.11.0.dev31","1.11.0.dev32","1.11.0.dev33","1.11.0.dev34","1.11.0.dev36","1.11.0.dev37","1.11.0.dev38","1.11.0.dev39","1.11.0.dev4","1.11.0.dev40","1.11.0.dev41","1.11.0.dev42","1.11.0.dev43","1.11.0.dev44","1.11.0.dev45","1.11.0.dev46","1.11.0.dev47","1.11.0.dev48","1.11.0.dev49","1.11.0.dev5","1.11.0.dev50","1.11.0.dev6","1.11.0.dev7","1.11.0.dev8","1.11.0.dev9","1.11.0rc1","1.11.0rc3","1.11.0rc4","1.11.0rc5","1.11.1","1.11.1rc0","1.11.1rc1","1.11.1rc2","1.11.2","1.11.2rc0","1.11.2rc1","1.11.2rc2","1.11.2rc3","1.11.3","1.11.3rc0","1.11.3rc1","1.11.4","1.11.4rc2","1.11.4rc3","1.11.5","1.11.6","1.12.0","1.12.0.dev0","1.12.0.dev1","1.12.0.dev10","1.12.0.dev11","1.12.0.dev12","1.12.0.dev13","1.12.0.dev14","1.12.0.dev15","1.12.0.dev16","1.12.0.dev17","1.12.0.dev18","1.12.0.dev19","1.12.0.dev2","1.12.0.dev20","1.12.0.dev21","1.12.0.dev22","1.12.0.dev23","1.12.0.dev24","1.12.0.dev25","1.12.0.dev26","1.12.0.dev27","1.12.0.dev28","1.12.0.dev29","1.12.0.dev3","1.12.0.dev30","1.12.0.dev31","1.12.0.dev32","1.12.0.dev33","1.12.0.dev34","1.12.0.dev35","1.12.0.dev36","1.12.0.dev37","1.12.0.dev38","1.12.0.dev39","1.12.0.dev4","1.12.0.dev40","1.12.0.dev41","1.12.0.dev42","1.12.0.dev43","1.12.0.dev44","1.12.0.dev45","1.12.0.dev5","1.12.0.dev6","1.12.0.dev7","1.12.0.dev8","1.12.0.dev9","1.12.0rc0","1.12.0rc1","1.12.0rc2","1.12.0rc3","1.12.0rc4","1.12.1","1.12.2","1.12.2rc0","1.12.2rc1","1.12.3","1.12.3rc0","1.12.4","1.12.4rc0","1.12.5rc0","1.13.0.dev0","1.13.0.dev1","1.13.0.dev10","1.13.0.dev11","1.13.0.dev12","1.13.0.dev13","1.13.0.dev14","1.13.0.dev15","1.13.0.dev16","1.13.0.dev17","1.13.0.dev18","1.13.0.dev19","1.13.0.dev2","1.13.0.dev20","1.13.0.dev21","1.13.0.dev22","1.13.0.dev23","1.13.0.dev24","1.13.0.dev25","1.13.0.dev26","1.13.0.dev27","1.13.0.dev28","1.13.0.dev29","1.13.0.dev3","1.13.0.dev30","1.13.0.dev31","1.13.0.dev32","1.13.0.dev33","1.13.0.dev4","1.13.0.dev5","1.13.0.dev6","1.13.0.dev7","1.13.0.dev8","1.13.0.dev9","1.7.2","1.7.3","1.8.0","1.8.0rc0","1.8.0rc1","1.8.0rc2","1.8.0rc3","1.8.0rc4","1.8.0rc5","1.8.0rc6","1.8.1","1.8.2","1.8.3","1.8.3rc0","1.8.4","1.9.0","1.9.1","1.9.2","1.9.3","1.9.3rc0","1.9.4","1.9.5","1.9.6","1.9.6rc0"],"database_specific":{"last_known_affected_version_range":"\u003c 1.10.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-qqw9-2vj9-hx7r/GHSA-qqw9-2vj9-hx7r.json"}}],"schema_version":"1.9.0"}