CVE-2026-10134 is a CWE-94 code-injection vulnerability in IBM Langflow OSS versions 1.0.0 through 1.9.3. PythonCodeStructuredTool executes attacker-controlled Python tool code with exec() during flow build processing. Where a flow containing this component is public, its build functionality can be invoked without authentication, causing server-side execution of the supplied tool code. An authenticated build path also exists for non-public flows.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
The repository contains a short README and one standalone Python PoC, poc.py, for CVE-2026-10134 affecting Langflow versions 1.0.0 through 1.9.3; it was reportedly tested on Ubuntu 22.04. It is not part of an exploit framework. The PoC accepts a Langflow URL, valid username/password, and an arbitrary shell command. It first authenticates to /api/v1/login, creates a PUBLIC flow through /api/v1/flows/, and embeds a custom PythonCodeStructuredTool component. That component imports subprocess and invokes the supplied command with shell=True. The script subsequently invokes the public temporary flow-build endpoint without an Authorization header, using only a JSON content type and arbitrary client_id cookie, then polls the corresponding event endpoint for an end event as execution confirmation. Although described as unauthenticated RCE, flow creation is authenticated; the unauthenticated portion is triggering a previously uploaded malicious public flow. A finally block attempts authenticated deletion of the created flow. The PoC is operational command-execution code rather than a detection-only script, but it does not expose captured command output to the operator.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unauthenticated remote code execution vulnerability in Langflow, referenced by a Metasploit exploit module.
A critical unauthenticated server-side remote code execution vulnerability in IBM Langflow OSS public flows via PythonCodeStructuredTool, affecting versions 1.0.0 through 1.9.3.
A critical unauthenticated server-side remote code execution vulnerability in Langflow OSS caused by attacker-controlled Python code being executed via exec() during flow build time, including a public-flow path that requires no authorization.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.