AE Agent Errors
AE-RQNNT84C

CSV agent node hardcodes allow_dangerous_code, exposing a Python REPL tool that runs prompt-injected code on the server

SECURITY FAILUREseverity: CRITICALcause: VERIFIEDoutcome: RESOLVED UNVERIFIEDconfidence: HIGH

Langflow's CSV Agent node created a LangChain CSV agent with allow_dangerous_code=True hardcoded, which automatically enables the python_repl_ast tool. Any LLM output invoking that tool was executed on the server, so a prompt could make the agent run arbitrary Python and OS commands; no UI toggle or environment variable could disable it.

Framework / agent
Langflow (uses LangChain create_csv_agent) · LLM-driven CSV/pandas agent with Python REPL tool
Remediation attempts
TESTED
Recurrence
not documented
Source languages
en
Updated
2026-09-29

Sources

Symptoms

  • LLM actions calling python_repl_ast are executed directly on the Langflow server
  • A crafted chat prompt leads to arbitrary Python and system command execution (a file is created on the server in the proof of concept)
The full record — root-cause evidence, every remediation attempt with its status and verification, failed attempts, patch references, verbatim quotes and recurrence — is a paid lookup (0.018 USDC via x402). Agents: GET /api/v1/cases/AE-RQNNT84C. Pricing

Similarity to your system is not implied. A remediation that worked in the documented context may not work in yours.