cbcvebase.

Ibm Langflow Oss vulnerabilities

141 known vulnerabilities affecting ibm/langflow_oss.

Total CVEs
141
CISA KEV
1
actively exploited
Public exploits
4
Exploited in wild
1
Severity breakdown
CRITICAL36HIGH73MEDIUM32

Vulnerabilities

Page 3 of 8
CVE-2026-14499P2HIGHCVSS 8.8≥ 1.0.0, ≤ 1.10.12026-07-17
CVE-2026-14499 [HIGH] CWE-78 CVE-2026-14499: IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user to execute arbitrar IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input in the Python Interpreter component.
nvd
CVE-2026-17632P2HIGHCVSS 8.8≥ 1.0.0, ≤ 1.10.32026-08-05
CVE-2026-17632 [HIGH] CWE-94 CVE-2026-17632: IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitra IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of Python code during AST-based security scanning.
nvd
CVE-2026-9196P2HIGHCVSS 8.8≥ 1.0.0, ≤ 1.10.32026-08-05
CVE-2026-9196 [HIGH] CWE-94 CVE-2026-9196: IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended co IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agentic Assistant validation due to improper handling of LLM‑generated components. The application executes model‑generated Python code in the backend during validation prior to user approval, which may allow an attacker to trigger side effects s
nvd
CVE-2026-9202P2CRITICALCVSS 9.8≥ 1.0.0, ≤ 1.10.02026-07-17
CVE-2026-9202 [CRITICAL] CWE-306 CVE-2026-9202: IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user acco IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_ACTIVE=true (documented deployment option), newly created accounts are immediately active and can authenticate to reach RCE endpoints, bypassing the need for AUTO_LOGIN.
nvd
CVE-2026-78569P2HIGHCVSS 8.8≥ 1.0.0, ≤ 1.11.52026-09-10
CVE-2026-78569 [HIGH] CWE-78 CVE-2026-78569: IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to execute arbitrary cod IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to execute arbitrary code due to an incomplete denylist in the security scanner.
nvd
CVE-2026-8182P3HIGHCVSS 8.8≥ 1.0.0, ≤ 1.10.32026-08-05
CVE-2026-8182 [HIGH] CWE-94 CVE-2026-8182: IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrar IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on the server without any credentials via 2 HTTP requests.
nvd
CVE-2026-81941P2HIGHCVSS 8.8≥ 1.0.0, ≤ 1.11.52026-09-10
CVE-2026-81941 [HIGH] CWE-284 CVE-2026-81941: IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute arbitrary operating system commands on the server at the privilege level of the application process by constructing a flow with an MCP Tools component configured to use a local stdio subprocess transport. This bypasses both the LANGFLOW_CUSTOM_COMPONENT_
nvd
CVE-2026-81211P2HIGHCVSS 8.8≥ 1.0.0, ≤ 1.11.52026-09-10
CVE-2026-81211 [HIGH] CWE-862 CVE-2026-81211: IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitra IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary Python code due to improper authorization of custom components in stored flows.
nvd
CVE-2026-97679P3HIGHCVSS 8.8≥ 1.0.0, ≤ 1.12.22026-10-07
CVE-2026-97679 [HIGH] CWE-94 CVE-2026-97679: IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitra IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command ('Code Injection') related to improper input validation.
nvd
CVE-2026-78571P3HIGHCVSS 8.8≥ 1.0.0, ≤ 1.11.52026-09-10
CVE-2026-78571 [HIGH] CWE-94 CVE-2026-78571: IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitra IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an unguarded eval() call on attacker-controlled input.
nvd
CVE-2026-79742P3HIGHCVSS 8.8≥ 1.0.0, ≤ 1.11.52026-09-10
CVE-2026-79742 [HIGH] CWE-94 CVE-2026-79742: IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitra IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an incomplete environment variable blocklist.
nvd
CVE-2026-17633P3HIGHCVSS 8.8≥ 1.0.0, ≤ 1.10.32026-08-05
CVE-2026-17633 [HIGH] CWE-94 CVE-2026-17633: IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitra IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to code injection.
nvd
CVE-2026-9201P3HIGHCVSS 8.8≥ 1.0.0, ≤ 1.10.32026-08-05
CVE-2026-9201 [HIGH] CWE-326 CVE-2026-9201: IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary cod IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryptographic weakness in the custom component validation mechanism. When the optional hardening mode that restricts execution to trusted component templates is enabled, the application validates component code using a truncated SHA‑256 hash. B
nvd
CVE-2026-97676P3HIGHCVSS 8.8≥ 1.0.0, ≤ 1.12.22026-10-07
CVE-2026-97676 [HIGH] CWE-94 CVE-2026-97676: IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitra IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in code, resulting in a sandbox escape.
nvd
CVE-2026-104335P3HIGHCVSS 8.8≥ 1.0.0, ≤ 1.12.22026-10-07
CVE-2026-104335 [HIGH] CWE-284 CVE-2026-104335: IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitra IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper access control.
nvd
CVE-2026-10140P3CRITICALCVSS 9.6≥ 1.0.0, ≤ 1.10.02026-06-30
CVE-2026-10140 [CRITICAL] CWE-639 CVE-2026-10140: IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling that allows IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling that allows reuse of API clients across tenant boundaries. An authenticated attacker can manipulate cache state to cause requests from other users to be processed using incorrect upstream API credentials, leading to cross-tenant billing and accountability misa
nvd
CVE-2026-8478P3HIGHCVSS 8.8≥ 1.0.0, ≤ 1.10.32026-08-05
CVE-2026-8478 [HIGH] CWE-94 CVE-2026-8478: IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input code.
nvd
CVE-2026-7667P3HIGHCVSS 8.8≥ 1.0.0, ≤ 1.10.02026-07-17
CVE-2026-7667 [HIGH] CWE-22 CVE-2026-7667: IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow po IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow pointing to an attacker-controlled URL that returns a specially crafted Content-Disposition header (e.g., filename="../../../target/path" ), enabling arbitrary file write operations with attacker-controlled content to any path accessible by the Langflow proc
nvd
CVE-2026-97678P3HIGHCVSS 8.8≥ 1.0.0, ≤ 1.12.22026-10-07
CVE-2026-97678 [HIGH] CWE-693 CVE-2026-97678: IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitra IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper input validation.
nvd
CVE-2026-97673P3HIGHCVSS 8.8≥ 1.0.0, ≤ 1.12.22026-10-07
CVE-2026-97673 [HIGH] CWE-693 CVE-2026-97673: IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitra IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper input validation.
nvd
Ibm Langflow Oss vulnerabilities | cvebase