Langflow AI CSV Agent Vulnerability Enables Remote Code Execution

Langflow AI CSV Agent Vulnerability Enables Remote Code Execution

First seen 2 Mar 2026, 15:11 UTC GbhackersCyberpressCybersecuritynews 51.6

Article Content

Browse articles
ThreatCluster

A security researcher disclosed a vulnerability (GHSA-3645-fxcv-hqr4) in the Langflow package on PyPI, which allows remote code execution attacks. The flaw specifically affects the CSV agent functionality within the open-source Langflow AI framework. Users of this package are advised to review their implementations and apply necessary mitigations.

Timeline

2026-02-25
GHSA-3645-fxcv-hqr4 disclosed by researcher Empreiteiro
2026-03-02
Articles published detailing the Langflow vulnerability