CVE-2026-18729 is an improper control of code generation vulnerability in IBM Langflow OSS versions 1.0.0 through 1.11.1. Insufficient enforcement of code-execution restrictions affects the PythonFunction component and the RunFlow private tweak channel. The PythonFunction component does not enforce the runtime code-execution gate used by other code-execution components, while the private tweak channel filters only a literal code field rather than applying the shared code-field blocking behavior. An authenticated remote attacker can bypass the allow_custom_components=false or LANGFLOW_ALLOW_CUSTOM_COMPONENTS=false hardening control and execute arbitrary code.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This two-file repository contains a README and a standalone Python PoC (poc.py) for CVE-2026-18729, described as an authenticated Langflow 1.10.0 remote code-execution flaw caused by unsafe exec()-based custom-component construction. The script checks the target version, authenticates using supplied credentials, obtains a bearer token, and posts a JSON body containing attacker-controlled Python under the code field to /api/v1/custom_component. Its default mode is an execution proof that causes a ZeroDivisionError during server-side component preparation. When -c/--command is provided, it creates a component whose top-level Python executes the supplied shell command through subprocess.check_output(..., shell=True). The response does not expose captured command output, but execution occurs before component metadata is returned. The PoC is a genuine, standalone operational exploit rather than a framework module or detection-only script.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Langflow authenticated remote code execution vulnerability for which the content indicates a Metasploit exploit module implementation.
A remote authenticated arbitrary-code-execution vulnerability in IBM Langflow OSS caused by improper control of code generation.
A high-severity (CVSS 8.8) remote authenticated arbitrary-code-execution vulnerability in IBM Langflow OSS versions 1.0.0 through 1.11.1, caused by insufficient enforcement of code-execution policies / improper control of code generation.
An authenticated remote code-execution vulnerability in Langflow OSS. The PythonFunction component lacks the runtime code-execution gate applied elsewhere, allowing an authenticated user to bypass the allow_custom_components=false policy through the RunFlow component's private tweak channel.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.