CVE-2026-101861 Langflow schema.py 不安全 eval 代码执行漏洞
影响认证攻击者可远程执行任意代码
Langflow 在 schema.py 中使用了不安全的 eval() 处理组件输入选项列表。攻击者可将带有恶意 __repr__ 方法的 Python 对象放入选项列表,当组件通过 ComponentToolkit.get_tools() 转换为 LangChain 工具时触发 eval(),从而实现代码执行。
影响范围
Langflow 1.0.16 至 1.12.0 之前版本,以及 0.0.94 至 1.12.0 之前版本。
漏洞详情
漏洞类型为不安全 eval() 导致的代码注入。成因是组件选项被插值进 Literal 类型字符串后直接传给 eval(),缺少安全求值控制。利用方式是攻击者将含恶意 __repr__ 的对象放入组件输入选项列表,在组件被转换为 LangChain 工具(包括通过 API 保存自定义组件)时触发执行。
利用条件与风险
利用需具备认证权限,可向组件输入选项列表注入恶意对象。成功利用后可执行任意代码,风险较高。
修复建议
建议升级至 Langflow 1.12.0 或更高版本。临时缓解措施包括限制组件创建与保存权限、避免不可信输入进入组件选项列表,暂无其他公开信息。
Langflow 1.0.16 before 1.12.0 and 0.0.94 before 1.12.0 contain an unsafe eval() vulnerability in schema.py that allows authenticated attackers to achieve code execution by placing a Python object with a malicious __repr__ method into component input options lists. The eval() sink is triggered when a component is converted into a LangChain tool via ComponentToolkit.get_tools(), including during custom component saves through the API, by interpolating options into a Literal type string that is passed directly to eval() without safe evaluation controls.