CVE-2026-51886
Langflow Code Injection Vulnerability Allows Arbitrary Code Execution.
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
A code injection vulnerability in langflow allows an authenticated attacker to execute arbitrary Python code on the server via an API endpoint. This could compromise service integrity and availability. The affected technology is a web-based application designed for workflows and APIs.