Fetching from the wire…
Public story · 2026-02-27 · source-backed
Langflow's CSV Agent node hardcodes allow_dangerous_code=True, exposing LangChain's python_repl_ast tool. Attackers inject prompts to execute arbitrary Python and OS commands without authentication. Patched in v1.8.0. This is the same eval() epidemic vulnerability class seen across agent workflow platforms — dangerous code execution shipped as default.
Each link below shares sources, entities, or timing with this story.
IBM's bulletin lists CVE-2026-85025, rated CVSS 9.8, which allows unauthenticated code execution through publicly shared MCP project endpoints in Langflow 1.0.0 through 1.11.5. CVE-2026-78575 and CVE-2026-81941 let authenticated users run OS commands through the MCP stdio serv...
LangChain, LangGraph, CrewAI, AutoGen, Microsoft Agent Framework, and Google ADK, presented at Black Hat (The Register). Insecure deserialization, SSRF, path traversal, use-after-free. That's the point: prompt-controlled content crosses into trusted framework logic, and then i...
OX Security researchers found a design-level flaw in Anthropic's Model Context Protocol STDIO transport that turns MCP tool invocations into OS command execution via configuration-to-command injection. Affected projects include LiteLLM (CVE-2026-30623, patched), Agent Zero, an...
Full 10.0. Network vector, low complexity, no authentication, no user interaction, high impact on confidentiality, integrity and availability. CVE-2026-79696, published September 9, is a code injection flaw in adk web affecting Google's Agent Development Kit for Python 2.0.0 t...
GHSA-533j-2v4q-mw5h (CVE-2026-55253, CVSS 7.7) covers MongoDBSaver.list() and MongoDBStore.search() accepting a filter without rejecting $-prefixed MongoDB operator keys, letting a caller who controls the filter read checkpoints outside their thread scope. Fixed in langgraph-c...
Copilot CLI through 0.0.422 is vulnerable to arbitrary code execution via bash parameter expansion. The safety check classifies commands as "read-only" based on visible text (e.g., echo), but shell operators (${var@P}, ${var=value}) execute hidden commands including reverse sh...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.