Ibm Langflow Oss vulnerabilities
141 known vulnerabilities affecting ibm/langflow_oss.
Total CVEs
141
CISA KEV
1
actively exploited
Public exploits
4
Exploited in wild
1
Severity breakdown
CRITICAL36HIGH73MEDIUM32
Vulnerabilities
Page 2 of 8
CVE-2026-7873P2CRITICALCVSS 9.9≥ 1.0.0, ≤ 1.10.02026-06-30
CVE-2026-7873 [CRITICAL] CWE-94 CVE-2026-7873: IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated attackers to execute arbitrary OS command
IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated attackers to execute arbitrary OS commands and read sensitive files including credentials, enabling complete system compromise and lateral movement.
nvd
CVE-2026-7663P2CRITICALCVSS 9.8≥ 1.0.0, ≤ 1.9.62026-06-30
CVE-2026-7663 [CRITICAL] CWE-285 CVE-2026-7663: IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP p
IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.
nvd
CVE-2026-7664P2CRITICALCVSS 9.8≥ 1.0.0, ≤ 1.8.42026-06-22
CVE-2026-7664 [CRITICAL] CWE-287 CVE-2026-7664: IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected MCP p
IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.
nvd
CVE-2026-17625P2HIGHCVSS 8.8≥ 1.0.0, ≤ 1.10.32026-08-05
CVE-2026-17625 [HIGH] CWE-78 CVE-2026-17625: IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.1
IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
nvd
CVE-2026-78575P2HIGHCVSS 8.8≥ 1.0.0, ≤ 1.11.52026-09-10
CVE-2026-78575 [HIGH] CWE-78 CVE-2026-78575: IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitra
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of command-line arguments in the MCP stdio server configuration.
nvd
CVE-2026-7803P2CRITICALCVSS 9.8≥ 1.0.0, ≤ 1.10.02026-06-30
CVE-2026-7803 [CRITICAL] CWE-20 CVE-2026-7803: IBM Langflow OSS 1.0.0 through 1.10.0 could allow arbitrary code execution due to improper validatio
IBM Langflow OSS 1.0.0 through 1.10.0 could allow arbitrary code execution due to improper validation of flow nodes with missing or empty component type fields.
nvd
CVE-2026-17623P2HIGHCVSS 8.8≥ 1.0.0, ≤ 1.10.32026-08-05
CVE-2026-17623 [HIGH] CWE-78 CVE-2026-17623: IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitra
IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of the command field in MCP server configurations.
nvd
CVE-2026-7755P2HIGHCVSS 8.8≥ 1.0.0, ≤ 1.10.02026-07-17
CVE-2026-7755 [HIGH] CWE-20 CVE-2026-7755: IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete v
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete validation enforcement on MCP server configuration files.
nvd
CVE-2026-12946P2CRITICALCVSS 9.9≥ 1.0.0, ≤ 1.10.02026-07-30
CVE-2026-12946 [CRITICAL] CWE-94 CVE-2026-12946: IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the
IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input code.
nvd
CVE-2026-81204P2CRITICALCVSS 9.8≥ 1.0.0, ≤ 1.11.52026-09-10
CVE-2026-81204 [CRITICAL] CWE-94 CVE-2026-81204: IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary code due to
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary code due to code injection during graph construction.
nvd
CVE-2026-7871P2CRITICALCVSS 9.8≥ 1.0.0, ≤ 1.10.02026-06-30
CVE-2026-7871 [CRITICAL] CWE-502 CVE-2026-7871: IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with
IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with full application privileges, compromising all secrets, data, and system integrity.
nvd
CVE-2026-13446P2CRITICALCVSS 9.8≥ 1.0.0, ≤ 1.10.12026-07-17
CVE-2026-13446 [CRITICAL] CWE-798 CVE-2026-13446: IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptog
IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
nvd
CVE-2026-19297P2CRITICALCVSS 9.1≥ 1.0.0, ≤ 1.9.62026-08-13
CVE-2026-19297 [CRITICAL] CWE-307 CVE-2026-19297: IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to
IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to improper restriction of excessive authentication attempts.
nvd
CVE-2026-81940P2HIGHCVSS 8.8≥ 1.0.0, ≤ 1.11.52026-09-10
CVE-2026-81940 [HIGH] CWE-94 CVE-2026-81940: IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitra
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special characters in flow display names.
nvd
CVE-2026-17630P2HIGHCVSS 8.8≥ 1.0.0, ≤ 1.10.32026-08-05
CVE-2026-17630 [HIGH] CWE-184 CVE-2026-17630: IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to execute arbitrary code due to
IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to execute arbitrary code due to improper validation of configuration parameters.
nvd
CVE-2026-76059P2HIGHCVSS 8.8≥ 1.0.0, ≤ 1.11.52026-09-10
CVE-2026-76059 [HIGH] CWE-693 CVE-2026-76059: IBM Langflow OSS 1.0.0 through 1.11.5 An attacker who could submit custom component source code coul
IBM Langflow OSS 1.0.0 through 1.11.5 An attacker who could submit custom component source code could bypass the static security scanner by crafting an annotated class-body assignment that resolved to a dangerous callable through alias tracking; the resolved value was never checked against the dangerous callable blocklist due to the logic error. If th
nvd
CVE-2026-17624P2HIGHCVSS 8.8≥ 1.0.0, ≤ 1.10.32026-08-05
CVE-2026-17624 [HIGH] CWE-94 CVE-2026-17624: IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.1
IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of module imports.
nvd
CVE-2026-19298P2HIGHCVSS 8.8≥ 1.0.0, ≤ 1.11.22026-09-04
CVE-2026-19298 [HIGH] CWE-94 CVE-2026-19298: IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to execute arbitra
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to execute arbitrary code due to an authorization bypass in the flow build process.
nvd
CVE-2026-104334P2CRITICALCVSS 9.8≥ 1.0.0, ≤ 1.12.22026-10-07
CVE-2026-104334 [CRITICAL] CWE-94 CVE-2026-104334: IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper control of code generation.
nvd
CVE-2026-84889P2HIGHCVSS 8.8≥ 1.0.0, ≤ 1.10.32026-09-10
CVE-2026-84889 [HIGH] CWE-22 CVE-2026-84889: IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitra
IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.
nvd