cbcvebase.

Ibm Langflow Oss vulnerabilities

141 known vulnerabilities affecting ibm/langflow_oss.

Total CVEs
141
CISA KEV
1
actively exploited
Public exploits
4
Exploited in wild
1
Severity breakdown
CRITICAL36HIGH73MEDIUM32

Vulnerabilities

Page 1 of 8
CVE-2026-9198P1CRITICALCVSS 9.8KEVPoC≥ 1.0.0, ≤ 1.10.02026-07-17
CVE-2026-9198 [CRITICAL] CWE-94 CVE-2026-9198: IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login ( IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments
nvd
CVE-2026-9103P2CRITICALCVSS 9.8PoC≥ 1.0.0, ≤ 1.10.02026-07-17
CVE-2026-9103 [CRITICAL] CWE-306 CVE-2026-9103: IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint. The endpoint issues long-lived superuser bearer tokens without requiring authentication when the AUTO_LOGIN configuration is enabled (enabled by default), which may allow an unauthent
nvd
CVE-2026-19295P2CRITICALCVSS 9.9PoC≥ 1.0.0, ≤ 1.11.12026-08-28
CVE-2026-19295 [CRITICAL] CWE-95 CVE-2026-19295: IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operatin IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with a crafted type field value and triggering a build of a wrapper flow that references it. This allowed privilege escalation from "authenticated flow user" to arbitrary OS-level command execu
nvd
CVE-2026-18729P2HIGHCVSS 8.8PoC≥ 1.0.0, ≤ 1.11.12026-08-28
CVE-2026-18729 [HIGH] CWE-94 CVE-2026-18729: IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitra IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitrary code due to improper control of generation of code.
nvd
CVE-2026-10561P2CRITICALCVSS 10.0≥ 1.0.0, ≤ 1.9.32026-06-22
CVE-2026-10561 [CRITICAL] CWE-94 CVE-2026-10561: IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python exe IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arbitrary code on the host system, resulting in complete compromise
nvd
CVE-2026-8476P2CRITICALCVSS 9.9≥ 1.0.0, ≤ 1.10.02026-07-17
CVE-2026-8476 [CRITICAL] CWE-502 CVE-2026-8476: IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching mechanism. The AsyncDiskCache class uses Python's unsafe pickle.loads() function to deserialize cached objects from disk without validation, integrity verification, or authentication, enabling arbitrary code execution when malicious
nvd
CVE-2026-8481P2CRITICALCVSS 9.9≥ 1.0.0, ≤ 1.10.02026-07-17
CVE-2026-8481 [CRITICAL] CWE-94 CVE-2026-8481: IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint. The POST /api/v1/validate/code endpoint accepts user-supplied Python code and executes it directly using Python's built-in exec() function without sandboxing, input validation, or privilege restrictions, enabling any authen
nvd
CVE-2026-13448P2CRITICALCVSS 9.8≥ 1.0.0, ≤ 1.10.12026-07-17
CVE-2026-13448 [CRITICAL] CWE-184 CVE-2026-13448: IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution vulnerability in the public flow build endpoint ( /api/v1/build_public_tmp/{flow_id}/flow ). The vulnerability stems from an incomplete denylist in the validate_public_flow_no_code_execution() function that fails to block several code-execution agent
nvd
CVE-2026-9135P2CRITICALCVSS 9.9≥ 1.0.0, ≤ 1.10.02026-07-17
CVE-2026-9135 [CRITICAL] CWE-94 CVE-2026-9135: IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163 IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulnerability in the Policies component's ToolGuard integration that bypasses the allow_custom_components=false security control. The vulnerability exists because the validation mechanism only checks the main
nvd
CVE-2026-79724P2CRITICALCVSS 9.8≥ 1.0.0, ≤ 1.11.52026-09-10
CVE-2026-79724 [CRITICAL] CWE-78 CVE-2026-79724: IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary OS commands IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.
nvd
CVE-2026-8505P2CRITICALCVSS 9.8≥ 1.0.0, ≤ 1.10.02026-07-17
CVE-2026-8505 [CRITICAL] CWE-306 CVE-2026-8505: IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the execution of any flow. The system incorrectly bypasses API key validation when the WEBHOOK_AUTH_ENABLE configuration is set to False (which is the default setting). This allows a remote attacker who knows a
nvd
CVE-2026-12944P2CRITICALCVSS 9.6≥ 1.0.0, ≤ 1.10.02026-09-14
CVE-2026-12944 [CRITICAL] CWE-918 CVE-2026-12944: IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by submitting components containing socket or urllib imports. This enables: (1) AWS credential theft via IMDSv1 SSRF with full IAM role permissions, (2) arbitrary file exfiltration from the container filesy
nvd
CVE-2026-8635P2CRITICALCVSS 9.9≥ 1.0.0, ≤ 1.10.02026-07-17
CVE-2026-8635 [CRITICAL] CWE-94 CVE-2026-8635: IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute arbitrary system commands, and achieve full system compromise with Langflow service permissions.
nvd
CVE-2026-8859P2CRITICALCVSS 9.9≥ 1.0.0, ≤ 1.10.02026-07-17
CVE-2026-8859 [CRITICAL] CWE-22 CVE-2026-8859: IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to u IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations due to improper input validation in the APIRequest component. A path traversal vulnerability exists when the "Save to File" feature is enabled, where filenames extracted from HTTP response Content-Disposition headers are not sanitiz
nvd
CVE-2026-85025P2CRITICALCVSS 9.8≥ 1.0.0, ≤ 1.11.52026-09-10
CVE-2026-85025 [CRITICAL] CWE-863 CVE-2026-85025: IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute ar IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and access or modify chat sessions through publicly shared MCP project endpoints due to improper enforcement of public-flow security restrictions and session isolation controls.
nvd
CVE-2026-10134P2CRITICALCVSS 10.0≥ 1.0.0, ≤ 1.9.32026-06-30
CVE-2026-10134 [CRITICAL] CWE-94 CVE-2026-10134: IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langfl IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process, read and modify every flow, conversation, message, file upload, and saved component in the Langflow database, can connect to internal services, abuse cloud metadata endpoints, laterally move to other tenants on the same Langflow instance,
nvd
CVE-2026-12940P2CRITICALCVSS 9.8≥ 1.0.0, ≤ 1.10.12026-07-30
CVE-2026-12940 [CRITICAL] CWE-78 CVE-2026-12940: IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote code execution via e IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launcher. The vulnerability exists in src/lfx/src/lfx/base/mcp/util.py where the DANGEROUS_ENV_VARS blocklist fails to include SHELLOPTS , BASHOPTS , and PS4 environment variables.
nvd
CVE-2026-7524P2CRITICALCVSS 9.8≥ 1.0.0, ≤ 1.9.12026-05-27
CVE-2026-7524 [CRITICAL] CWE-22 CVE-2026-7524: IBM Langflow OSS 1.0.0 through 1.9.1 could allow remote code execution due to improper validation of IBM Langflow OSS 1.0.0 through 1.9.1 could allow remote code execution due to improper validation of symbolic links during archive extraction.
nvd
CVE-2026-19286P2CRITICALCVSS 9.8≥ 1.0.0, ≤ 1.11.12026-08-28
CVE-2026-19286 [CRITICAL] CWE-94 CVE-2026-19286: IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper enforcement of security restrictions on the A2A public endpoint.
nvd
CVE-2026-93674P2CRITICALCVSS 9.8≥ 1.0.0, ≤ 1.12.22026-10-07
CVE-2026-93674 [CRITICAL] CWE-94 CVE-2026-93674: IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
nvd