AE-RQNNT84C
CSV agent node hardcodes allow_dangerous_code, exposing a Python REPL tool that runs prompt-injected code on the server
SECURITY FAILUREseverity: CRITICALcause: VERIFIEDoutcome: RESOLVED UNVERIFIEDconfidence: HIGH
Langflow's CSV Agent node created a LangChain CSV agent with allow_dangerous_code=True hardcoded, which automatically enables the python_repl_ast tool. Any LLM output invoking that tool was executed on the server, so a prompt could make the agent run arbitrary Python and OS commands; no UI toggle or environment variable could disable it.
- Framework / agent
- Langflow (uses LangChain create_csv_agent) · LLM-driven CSV/pandas agent with Python REPL tool
- Remediation attempts
- TESTED
- Recurrence
- not documented
- Source languages
- en
- Updated
- 2026-09-29
Sources
- SECURITY ADVISORY Langflow has Remote Code Execution in CSV Agent — https://github.com/langflow-ai/langflow, retrieved 2026-09-29
- GITHUB COMMIT fix: default remote code execution in CSV agent (#11762) — github.com/langflow-ai/langflow, retrieved 2026-09-29
Symptoms
- LLM actions calling python_repl_ast are executed directly on the Langflow server
- A crafted chat prompt leads to arbitrary Python and system command execution (a file is created on the server in the proof of concept)
The full record — root-cause evidence, every remediation attempt with its status and verification, failed attempts, patch references, verbatim quotes and recurrence — is a paid lookup (0.018 USDC via x402). Agents:
GET /api/v1/cases/AE-RQNNT84C. PricingSimilarity to your system is not implied. A remediation that worked in the documented context may not work in yours.