[23:10:42] project cache present at /pruva/project-cache/repo (source reference only) c979695ce660285b267b3e7c6788e91aade3c0fe fec71dca901949c09ed4d63315804337cd2eb13d vuln_image=langflowai/langflow@sha256:79c02794adebe82d756b7152ce4feebe4a5426e1faf3fe5b5d0dd08f304510c4 fixed_image=langflowai/langflow@sha256:34055a07d446de51760e28dab6332e22624e5f48dca611567779992fc32c5ec0 fix_commit=461506ac2f38f70a994b5140572b876448c11e4c vuln_tag_sha=c979695ce660285b267b3e7c6788e91aade3c0fe (v1.12.2) fixed_tag_sha=fec71dca901949c09ed4d63315804337cd2eb13d (v1.12.3) vuln_id=sha256:3860041d6472cde9e9a3a9da2086dfcd50b6222c6f795c7a2713414ad313be8e fixed_id=sha256:d147274a59d021a5b299e422f0292b021cc9b3ca0401958220e2793d2fbdb5f8 d5b270b83d7bdc946e9a9cd35c2943d08bcc5a2ec94fe451364e9b5ca235ae13 [23:11:08] pruva-cve674-vuln-1-1791501042-8972 healthy on :7860 [23:11:08] [vuln-1] obtained superuser token with NO credentials (auto_login) [23:11:08] [vuln-1] plant HTTP=200 [23:11:08] [vuln-1] planted module pruva_planted_17915010428972_1.py confirmed in site-packages [23:11:09] [vuln-1] trigger HTTP=500 response={"detail":"PLANTED_EXEC:PRUVA-CVE-2026-93674-1791501042-8972-VULN-1:uid=1000(user) gid=0(root) groups=0(root)"} [23:11:09] [vuln-1] marker_present=yes exec_in_response=yes [23:11:09] [vuln-1] VULNERABLE: validate/code executed attacker module; marker: PRUVA-CVE-2026-93674-1791501042-8972-VULN-1 uid=1000(user) gid=0(root) groups=0(root) 4cb3cbf32bdfe16ef8dc5eef1363e776d04de99057905de1f89dbd247678c7a0 [23:11:33] pruva-cve674-vuln-2-1791501042-8972 healthy on :7862 [23:11:33] [vuln-2] obtained superuser token with NO credentials (auto_login) [23:11:33] [vuln-2] plant HTTP=200 [23:11:33] [vuln-2] planted module pruva_planted_17915010428972_2.py confirmed in site-packages [23:11:34] [vuln-2] trigger HTTP=500 response={"detail":"PLANTED_EXEC:PRUVA-CVE-2026-93674-1791501042-8972-VULN-2:uid=1000(user) gid=0(root) groups=0(root)"} [23:11:34] [vuln-2] marker_present=yes exec_in_response=yes [23:11:34] [vuln-2] VULNERABLE: validate/code executed attacker module; marker: PRUVA-CVE-2026-93674-1791501042-8972-VULN-2 uid=1000(user) gid=0(root) groups=0(root) 8f6e3900abae225e00d3ea8d307f7dd766b8a6433ecdfe0516542e6cdf7633a4 [23:12:00] pruva-cve674-fixed-1-1791501042-8972 healthy on :7861 [23:12:00] [fixed-1] obtained superuser token with NO credentials (auto_login) [23:12:00] [fixed-1] plant HTTP=200 [23:12:00] [fixed-1] planted module pruva_planted_17915010428972_1.py confirmed in site-packages [23:12:00] [fixed-1] trigger HTTP=200 response={"imports":{"errors":[]},"function":{"errors":[]}} [23:12:01] [fixed-1] marker_present=no exec_in_response=no [23:12:01] [fixed-1] FIXED: validate/code located but did NOT execute the module 8391afbebe20f99f54016ba139cbd81ff2ca49a12b6d5b8bc0adfce58f91f645 [23:12:26] pruva-cve674-fixed-2-1791501042-8972 healthy on :7863 [23:12:26] [fixed-2] obtained superuser token with NO credentials (auto_login) [23:12:26] [fixed-2] plant HTTP=200 [23:12:26] [fixed-2] planted module pruva_planted_17915010428972_2.py confirmed in site-packages [23:12:26] [fixed-2] trigger HTTP=200 response={"imports":{"errors":[]},"function":{"errors":[]}} [23:12:26] [fixed-2] marker_present=no exec_in_response=no [23:12:26] [fixed-2] FIXED: validate/code located but did NOT execute the module [23:12:26] summary: vuln_ok=2/2 fixed_ok=2/2 [23:12:26] RESULT: CVE-2026-93674 CONFIRMED (2/2 vulnerable executions, 2/2 fixed non-executions)