CVE-2026-14499
published 2026-07-17CVE-2026-14499: IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to…
PriorityP260high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.66%
50.0th percentile
IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input in the Python Interpreter component.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | langflow_oss | 1.0.0 – 1.10.1 | — |
| langflow | langflow | >= 1.0.0 < 1.10.2 | 1.10.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
IBM Langflow OSS up to 1.10.1 Python Interpreter os command injection (EUVD-2026-45306)
vuldb·2026-07-17·CVSS 8.8
CVE-2026-14499 [HIGH] IBM Langflow OSS up to 1.10.1 Python Interpreter os command injection (EUVD-2026-45306)
A vulnerability was found in IBM Langflow OSS up to 1.10.1 and classified as problematic. Affected is an unknown function of the component Python Interpreter. The manipulation results in os command injection.
This vulnerability is known as CVE-2026-14499. It is possible to launch the attack remotely. No exploit is available.
GHSA
IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input
ghsa_unreviewed·2026-07-17
CVE-2026-14499 [HIGH] CWE-78 IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input
IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input in the Python Interpreter component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-17
Published