cbcvebase.

Ibm Langflow Oss vulnerabilities

141 known vulnerabilities affecting ibm/langflow_oss.

Total CVEs
141
CISA KEV
1
actively exploited
Public exploits
4
Exploited in wild
1
Severity breakdown
CRITICAL36HIGH73MEDIUM32

Vulnerabilities

Page 4 of 8
CVE-2026-8056P3HIGHCVSS 8.8≥ 1.0.0, ≤ 1.10.02026-07-17
CVE-2026-8056 [HIGH] CWE-94 CVE-2026-8056: IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at runtime via the API. A critical security flaw exists in the parameter filtering mechanism within the `apply_tweaks()` function.
nvd
CVE-2026-88962P3HIGHCVSS 8.8≥ 1.0.0, ≤ 1.12.22026-10-07
CVE-2026-88962 [HIGH] CWE-94 CVE-2026-88962: IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitra IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper control of code generation.
nvd
CVE-2026-9077P3HIGHCVSS 8.5≥ 1.0.0, ≤ 1.10.32026-08-05
CVE-2026-9077 [HIGH] CWE-807 CVE-2026-9077: IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass local IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only restrictions and write arbitrary MCP server configurations to IDE configuration files on the host system.
nvd
CVE-2026-97674P3HIGHCVSS 8.1≥ 1.0.0, ≤ 1.12.22026-10-07
CVE-2026-97674 [HIGH] CWE-94 CVE-2026-97674: IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitra IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command ('Code Injection'), aka improper control of code generation.
nvd
CVE-2026-13435P3CRITICALCVSS 9.9≥ 1.0.0, ≤ 1.10.12026-07-30
CVE-2026-13435 [CRITICAL] CWE-94 CVE-2026-13435: IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the Pyt IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox implementation.
nvd
CVE-2026-10560P3CRITICALCVSS 9.1≥ 1.0.0, ≤ 1.9.62026-06-30
CVE-2026-10560 [CRITICAL] CWE-287 CVE-2026-10560: IBM Langflow OSS 1.0.0 through 1.9.6 contains a missing authentication vulnerability in /api/v1/buil IBM Langflow OSS 1.0.0 through 1.9.6 contains a missing authentication vulnerability in /api/v1/build_public_tmp/ endpoints that allows an unauthenticated attacker to read build event data or cancel jobs using a valid job identifier, resulting in information disclosure and denial of service.
nvd
CVE-2026-7872P3HIGHCVSS 8.1≥ 1.0.0, ≤ 1.10.02026-07-17
CVE-2026-7872 [HIGH] CWE-22 CVE-2026-7872: IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files inclu IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files including the JWT signing key and forge authentication tokens for any user.
nvd
CVE-2026-97655P3HIGHCVSS 8.8≥ 1.0.0, ≤ 1.12.22026-10-07
CVE-2026-97655 [HIGH] CWE-94 CVE-2026-97655: IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to an incomplete blocklist in the code security scanner.
nvd
CVE-2026-10129P3HIGHCVSS 8.5≥ 1.0.0, ≤ 1.9.32026-06-30
CVE-2026-10129 [HIGH] CWE-918 CVE-2026-10129: IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) protection bypass IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) protection bypass vulnerability in the API Request component. An authenticated attacker with low-level privileges (flow author role) can bypass SSRF protections by enabling the follow_redirects parameter and supplying a public URL that redirects to internal/localhost ad
nvd
CVE-2026-93449P3HIGHCVSS 8.5≥ 1.0.0, ≤ 1.12.22026-10-07
CVE-2026-93449 [HIGH] CWE-94 CVE-2026-93449: IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitra IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper control of code generation.
nvd
CVE-2026-8183P3HIGHCVSS 7.7≥ 1.0.0, ≤ 1.10.32026-08-05
CVE-2026-8183 [HIGH] CWE-22 CVE-2026-8183: IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.1 IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. /) to v i ew arbitrary files on the system
nvd
CVE-2026-8470P3CRITICALCVSS 9.1≥ 1.0.0, ≤ 1.10.32026-08-05
CVE-2026-8470 [CRITICAL] CWE-327 CVE-2026-8470: IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's non-cryptographic random module for generating Fernet encryption keys from user secrets under 32 characters. The deterministic Mersenne Twister PRNG produces identical keys for identical seeds, allowing attackers to reproduce encr
nvd
CVE-2026-17626P3HIGHCVSS 8.8≥ 1.0.0, ≤ 1.10.32026-08-05
CVE-2026-17626 [HIGH] CWE-266 CVE-2026-17626: IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expose sensitive host files via Docker-based MCP servers due to incomplete filtering of dangerous Docker volume-mount and device-mapping arguments.
nvd
CVE-2026-13445P3HIGHCVSS 8.1≥ 1.0.0, ≤ 1.10.12026-07-17
CVE-2026-13445 [HIGH] CWE-639 CVE-2026-13445: IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component to read and modify another user's uploaded files by specifying absolute paths pointing to victim storage locations. In append mode, the attacker's workflow reads victim file contents, appends attacker-controlled data, and uploads a copy contain
nvd
CVE-2026-18891P3HIGHCVSS 8.2≥ 1.0.0, ≤ 1.11.12026-08-28
CVE-2026-18891 [HIGH] CWE-287 CVE-2026-18891: IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary flows and a IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary flows and access sensitive information due to improper authentication.
nvd
CVE-2026-19306P3HIGHCVSS 7.7≥ 1.0.0, ≤ 1.11.22026-09-04
CVE-2026-19306 [HIGH] CWE-22 CVE-2026-19306: IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files from IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files from the server filesystem — including server secret material (secret_key, JWT signing keys, the application database, /proc/self/environ, and other tenants' upload directories) — by supplying absolute paths or traversal sequences in the files parameter of an
nvd
CVE-2026-12942P3HIGHCVSS 7.5≥ 1.0.0, ≤ 1.10.12026-07-30
CVE-2026-12942 [HIGH] CWE-22 CVE-2026-12942: IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to traverse directories on the s IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. /) to view arbitrary files on the system.
nvd
CVE-2026-7874P3CRITICALCVSS 9.1≥ 1.0.0, ≤ 1.10.02026-06-30
CVE-2026-7874 [CRITICAL] CWE-338 CVE-2026-7874: IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow disclosure of all stored credentials due IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow disclosure of all stored credentials due to the use of a weak and reversible key derivation mechanism for encryption at rest.
nvd
CVE-2026-93675P3HIGHCVSS 8.8≥ 1.0.0, ≤ 1.12.22026-10-07
CVE-2026-93675 [HIGH] CWE-440 CVE-2026-93675: IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to an expected dependency confusion.
nvd
CVE-2026-19875P3HIGHCVSS 7.5≥ 1.0.0, ≤ 1.10.02026-08-19
CVE-2026-19875 [HIGH] CWE-306 CVE-2026-19875: IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to overwrite administrator email IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to overwrite administrator email information and abuse the server as an outbound relay due to missing authentication for the registration endpoint.
nvd
Ibm Langflow Oss vulnerabilities | cvebase