CVE-2024-48061
CRITICALlangflow <=1.0.18 - Remote Code Execution via Unsafe Component Code Execution
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-48061. PoCs published by BwithE.
AI-analyzed exploit summary This PoC exploits a remote code execution vulnerability in Langflow via the `/api/v1/validate/code` endpoint. It sends a crafted payload to spawn a reverse shell connecting back to a listener.
Description
langflow <=1.0.18 is vulnerable to Remote Code Execution (RCE) as any component provided the code functionality and the components run on the local machine rather than in a sandbox.
Exploits (1)
nomisec
WORKING POC
by BwithE · poc
https://github.com/BwithE/CVE-2024-48061
This PoC exploits a remote code execution vulnerability in Langflow via the `/api/v1/validate/code` endpoint. It sends a crafted payload to spawn a reverse shell connecting back to a listener.
Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target:
Langflow (version not specified)
No auth needed
Prerequisites:
Network access to the target · Target must have the vulnerable endpoint exposed
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (2)
Core 2
Core References
Third Party Advisory
https://gist.github.com/AfterSnows/1e58257867002462923fd62dde2b5d61
Scores
CVSS v3
9.8
EPSS
0.1320
EPSS Percentile
94.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
total
Details
CWE
CWE-94
Status
published
Products (2)
langflow/langflow
< 1.0.18
pypi/langflow
0PyPI
Published
Nov 04, 2024
Tracked Since
Feb 18, 2026