CVE-2026-101861 | langflow-ai Langflow up to 1.11.x Component Toolkit schema.py ComponentToolkit.get_tools code injection
A vulnerability, which was classified as critical, has been found in langflow-ai Langflow up to 1.11.x. Impacted is the function ComponentToolkit.get_tools of the file schema.py of the component Component Toolkit. This manipulation causes code injection.
This vulnerability is tracked as CVE-2026-101861. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More