CVE-2026-8481
published 2026-07-17CVE-2026-8481: IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint. The POST…
PriorityP271critical9.9CVSS 3.1
AVNACLPRLUINSCCHIHAH
EPSS
0.81%
55.3th percentile
IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint. The POST /api/v1/validate/code endpoint accepts user-supplied Python code and executes it directly using Python's built-in exec() function without sandboxing, input validation, or privilege restrictions, enabling any authenticated user to execute arbitrary system commands with the full privileges of the Langflow server process.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | langflow_oss | 1.0.0 – 1.10.0 | — |
| langflow | langflow | >= 1.0.0 < 1.10.1 | 1.10.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
IBM Langflow up to 1.10.0 Code Validation API Endpoint /api/v1/validate/code exec sandbox
vuldb·2026-07-18·CVSS 9.9
CVE-2026-8481 [CRITICAL] IBM Langflow up to 1.10.0 Code Validation API Endpoint /api/v1/validate/code exec sandbox
A vulnerability classified as critical has been found in IBM Langflow up to 1.10.0. The affected element is the function exec of the file /api/v1/validate/code of the component Code Validation API Endpoint. Performing a manipulation results in sandbox issue.
This vulnerability is identified as CVE-2026-8481. The attack can be initiated remotely. There is not any exploit available.
GHSA
IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint.
ghsa_unreviewed·2026-07-17
CVE-2026-8481 [CRITICAL] CWE-94 IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint.
IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint. The POST /api/v1/validate/code endpoint accepts user-supplied Python code and executes it directly using Python's built-in exec() function without sandboxing, input validation, or privilege restrictions, enabling any authenticated user to execute arbitrary system commands with the full privileges of the Langflow server process.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-17
Published