CVE-2026-79742
published 2026-09-10CVE-2026-79742: IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an incomplete environment variable blocklist.
PriorityP358high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.81%
55.4th percentile
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an incomplete environment variable blocklist.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | langflow_oss | 1.0.0 – 1.11.5 | — |
| langflow | langflow | >= 1.0.0 < 1.11.6 | 1.11.6 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an incomplete environment variable blocklist.
ghsa_unreviewed·2026-09-11
CVE-2026-79742 [HIGH] CWE-94 IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an incomplete environment variable blocklist.
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an incomplete environment variable blocklist.
VulDB
IBM Langflow OSS up to 1.11.5 input validation
vuldb·2026-09-10·CVSS 8.8
CVE-2026-79742 [HIGH] IBM Langflow OSS up to 1.11.5 input validation
A vulnerability has been found in IBM Langflow OSS up to 1.11.5 and classified as critical. This vulnerability affects unknown code. The manipulation leads to improper input validation.
This vulnerability is documented as CVE-2026-79742. The attack can be initiated remotely. There is not any exploit available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-10
Published