CVE•Published 2026-02-26•1 article on news•7 live references•NVD data
CVE-2026-27966
Vulnerability data via CVEDB (Shodan)
CVSS v3.1
9.8
CRITICAL
EPSS percentile
98
Exploit Prediction Scoring System · top 2% of all CVEs
Description
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.8.0, the CSV Agent node in Langflow hardcodes `allow_dangerous_code=True`, which automatically exposes LangChain’s Python REPL tool (`python_repl_ast`). As a result, an attacker can execute arbitrary Python and OS commands on the server via prompt injection, leading to full Remote Code Execution (RCE). Version 1.8.0 fixes the issue.
Timeline
Published 2026-02-26
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
Shodan · vuln tag1,139 hosts
vuln:CVE-2026-27966Hosts Shodan has explicitly fingerprinted as vulnerable.
Shodan · product
product:"Langflow Langflow"All exposed Langflow Langflow instances — cross-reference with the CVE's affected-version range.
Shodan · banner/body mention
http.html:"Langflow"HTTP body or banner mentions "Langflow" — catches deploys Shodan didn't identify as a product.
More intel sources (5)
Shodan report
vuln:CVE-2026-27966Country / ASN / product breakdown for the vuln query.
Censys
vulnerabilities.cve_id: CVE-2026-27966Censys host search filtered to this CVE id.
grep.app
CVE-2026-27966Public source-code mentions — fast PoC discovery.
GitHub code
CVE-2026-27966GitHub code search for direct mentions.
Google dork
"CVE-2026-27966" exploit -site:nvd.nist.govWrite-ups and news, NVD excluded.
Known PoCs on GitHub (6)
CVE-2026-279666 repos
Threekiii/Awesome-POCJava
一个漏洞 PoC 知识库。A knowledge base for vulnerability PoCs(Proof of Concept), with 1k+ vulnerabilities.
Threekiii/CVEunknown
一个 CVE 漏洞预警知识库,无 exp/poc,部分包含修复方案。A knowledge base of CVE security vulnerability, no PoCs/exploits.
DarkFunct/TK-CVE-RepoPython
TK-CVE-Repo
J1ezds/Vulnerability-Wiki-pageHTML
这是一个每天同步Vulnerability-Wiki中docs-base中内容的项目
Anon-Cyber-Team/CVE-2026-27966--RCE-in-LangflowPython
Exploit Tools For new CVE
lieling-xyz/aiHoneyPotFrameworkPython
aiHoneyPotFramework