Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-51886

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Langflow-ai Langflow v1.9.3 存在代码注入漏洞。该漏洞的影响为:可远程执行任意代码。受影响组件为: 中的 端点(具体涉及对 的已认证 HTTP POST 请求)。攻击向量:通过 HTTP 或基于浏览器的服务路径进行攻击。一个面向公众的路由接收原始 Python 源代码,并将其直接送入服务端编译/执行的验证流程,且未设置任何可见的权限控制或安全限制。 在 Langflow-ai Langflow(版本截至 1.9.3)中发现了一个弱点。langflow 在 端点(对应代码文件 第13行)中存

AI Predicted 8.8 Difficulty: Easy EPSS 0.17% · P6

Possible ATT&CK Techniques 1 AI

T1059 · Command and Scripting Interpreter

Affected Version Matrix 1

VendorProduct Version RangeStatus
n/a n/a n/a affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-51886

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
langflow-ai langflow v1.9.3 is affected by: Code Injection. The impact is: execute arbitrary code (remote). The component is: src/backend/base/langflow/api/v1/validate.py:validate-post_validate_code-a-real-authenticated-http-post-to-api-v1. The attack vector is: Attack surface: HTTP or browser-backed service path. A public-facing route accepts raw Python source and forwards it into a server-side compile/exec validation path without any visible entitlement guard. ¶¶ A weakness has been identified in langflow-ai langflow up to 1.9.3. langflow contains a code injection vulnerability in validate-post_validate_code-a-real-authenticated-http-post-to-api-v1 (src/backend/base/langflow/api/v1/validate.py:13). An authenticated attacker can execute arbitrary Python code on the server by submitting malicious code to the /api/v1/validate/code endpoint, which directly executes user-supplied code without sandboxing or security controls.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2026-51886

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-51886

请登录查看更多情报信息。

Proof of Concept for CVE-2026-51886 (1)

Other References for CVE-2026-51886 (1)

Same Patch Batch · n/a · 2026-10-01 · 21 CVEs total

CVE-2026-103484 8.8 HIGH pgvector buffer overflow in IVFFlat index build
CVE-2026-103531 5.5 MEDIUM OpenSC card-setcos.c setcos_construct_fci_44 stack-based overflow
CVE-2026-51876 DeepTutor 1.4.0授权绕过漏洞
CVE-2026-51875 Devika v1.0存在路径遍历漏洞
CVE-2026-51892 RagFlow 0.24.0 /v1/document/get/ 接口访问控制错误漏洞
CVE-2026-51896 RagFlow 0.25.3恢复模块越权访问漏洞
CVE-2026-51882 Langchain-Chatchat 0.3.0 文件上传路径穿越漏洞
CVE-2026-51878 DeepTutor 1.4.0 对象标识符授权绕过漏洞
CVE-2026-51873 Devika v1.0目录遍历漏洞
CVE-2026-51881 DeepTutor 1.4.0远程代码注入漏洞
CVE-2026-51879 DeepTutor 1.4.0 认证绕过漏洞
CVE-2026-51897 RAGFlow 0.24.0 get_dataset接口存在命令执行漏洞
CVE-2026-51884 Langchain Chatchat 0.3.1临时文档上传路径遍历漏洞
CVE-2026-51888 Langflow v1.8.4 目录遍历漏洞
CVE-2026-51893 RagFlow 0.24.0 越权访问漏洞
CVE-2026-51880 Deeptutor 1.4.0 EditFileTool路径遍历漏洞
CVE-2026-51895 Ragflow 0.24.0及之前版本存在更新元数据不当访问控制漏洞
CVE-2026-51874 Devika v1.0路径穿越漏洞
CVE-2026-51894 RAGFlow 0.24.0 任意文件读取漏洞
CVE-2026-51883 Langchain-Chatchat 0.3.x 知识库创建接口路径穿越漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-51886

No comments yet


Leave a comment