CVEPublished 2026-02-261 article on news7 live referencesNVD data

CVE-2026-27966

Vulnerability data via CVEDB (Shodan)

CVSS v3.1
9.8
CRITICAL
EPSS percentile
98
Exploit Prediction Scoring System · top 2% of all CVEs
Description

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.8.0, the CSV Agent node in Langflow hardcodes `allow_dangerous_code=True`, which automatically exposes LangChain’s Python REPL tool (`python_repl_ast`). As a result, an attacker can execute arbitrary Python and OS commands on the server via prompt injection, leading to full Remote Code Execution (RCE). Version 1.8.0 fixes the issue.

Timeline
Published 2026-02-26

External references

Search for exposed instances

Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).

More intel sources (5)

Known PoCs on GitHub (6)