CVE-2026-9198
published 2026-07-17CVE-2026-9198: IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with…
PriorityP197critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2026-08-07
Exploited in the wild
EPSS
34.73%
98.3th percentile
IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | langflow_oss | 1.0.0 – 1.10.0 | — |
| langflow | langflow | >= 1.0.0 < 1.10.1 | 1.10.1 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
IBM Langflow OSS up to 1.10.0 Code Execution exec os command injection (EUVD-2026-45236 / Nessus ID 333371)
vuldb·2026-08-08·CVSS 9.8
CVE-2026-9198 [CRITICAL] IBM Langflow OSS up to 1.10.0 Code Execution exec os command injection (EUVD-2026-45236 / Nessus ID 333371)
A vulnerability, which was classified as critical, has been found in IBM Langflow OSS up to 1.10.0. The affected element is the function exec of the component Code Execution Handler. This manipulation causes os command injection.
This vulnerability is handled as CVE-2026-9198. The attack can be initiated remotely. Additionally, an exploit exists.
GHSA
IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exe
ghsa_unreviewed·2026-07-17
CVE-2026-9198 [CRITICAL] CWE-94 IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exe
IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments
VulnCheck
IBM Langflow Code Injection Vulnerability
vulncheck·2026·CVSS 9.8
CVE-2026-9198 [CRITICAL] CWE-94 IBM Langflow Code Injection Vulnerability
IBM Langflow Code Injection Vulnerability
Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.
Affected: IBM Langflow
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Exploitation References: https://kevintel.com/CVE-2026-9198; https:
CISA
IBM Langflow Code Injection Vulnerability
cisa·2026-08-04·CVSS 9.8
CVE-2026-9198 [CRITICAL] CWE-94 IBM Langflow Code Injection Vulnerability
Vulnerability: IBM Langflow Code Injection Vulnerability
Affected: IBM Langflow
Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Notes: https://www.ibm.com/support/pages/node/7278927
No detection rules found.
Metasploit
Langflow AI auto_login RCE
metasploit
CVE-2026-9198 Langflow AI auto_login RCE
Langflow AI auto_login RCE
Langflow versions 1.10.0 and below are susceptible to unauthenticated remote code execution. By chaining /api/v1/auto_login with /api/v1/validate/code, a remote unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.
Nuclei
IBM Langflow - Remote Code Execution
nuclei·CVSS 9.8
CVE-2026-9198 [CRITICAL] IBM Langflow - Remote Code Execution
IBM Langflow - Remote Code Execution
IBM Langflow OSS 1.0.0 through 1.10.0 contains a remote code execution caused by chaining /api/v1/auto_login and /api/v1/validate/code endpoints, letting unauthenticated attackers execute arbitrary code remotely, exploit requires no authentication.
Template:
id: CVE-2026-9198
info:
name: IBM Langflow - Remote Code Execution
author: YesWeHack
severity: critical
description: |
IBM Langflow OSS 1.0.0 through 1.10.0 contains a remote code execution caused by chaining /api/v1/auto_login and /api/v1/validate/code endpoints, letting unauthenticated attackers execute arbitrary code remotely, exploit requires no authentication.
impact: |
Unauthenticated attackers can execute arbitrary code remotely, leading to full system compromise.
remediation: |
Update to
2026-07-17
Published
2026-08-04
Added to CISA KEV
Exploited in the wild