CVE-2026-18729
published 2026-08-28CVE-2026-18729: IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitrary code due to improper control of generation of code.
PriorityP268high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EXPLOIT
EPSS
1.95%
79.4th percentile
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitrary code due to improper control of generation of code.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | langflow_oss | 1.0.0 – 1.11.1 | — |
| langflow | langflow | >= 1.0.0 < 1.11.2 | 1.11.2 |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
IBM Langflow OSS up to 1.11.1 code injection
vuldb·2026-08-29·CVSS 8.8
CVE-2026-18729 [HIGH] IBM Langflow OSS up to 1.11.1 code injection
A vulnerability categorized as critical has been discovered in IBM Langflow OSS up to 1.11.1. Affected by this issue is some unknown functionality. The manipulation results in code injection.
This vulnerability is identified as CVE-2026-18729. The attack can be executed remotely. There is not any exploit available.
GHSA
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitrary code due to improper control of generation of code.
ghsa_unreviewed·2026-08-29
CVE-2026-18729 [HIGH] CWE-94 IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitrary code due to improper control of generation of code.
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitrary code due to improper control of generation of code.
No detection rules found.
No public exploits indexed.
2026-08-28
Published