IBM Langflow OSS

50 known vulnerabilities in IBM Langflow OSS, 7 critical, 1 actively exploited, with patch priority, exploit likelihood and the news covering them.

Recently exploited

  • CVE-2026-9198 CVSS 9.8 critical · actively exploited IBM Langflow Code Injection Vulnerability

Latest vulnerabilities

  • CVE-2026-12944 CVSS 9.6 critical IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow…
  • CVE-2026-12767 CVSS 6.5 medium IBM Langflow OSS 1.0.0 through 1.11.5 is vulnerable to server-side request forgery (SSRF). This may allow an unauthenticated attacker to…
  • CVE-2026-12766 CVSS 5.4 medium IBM Langflow OSS 1.0.0 through 1.11.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to…
  • CVE-2026-12765 CVSS 6.5 medium IBM Langflow OSS 1.0.0 through 1.10.2 is vulnerable to server-side request forgery (SSRF). This may allow an unauthenticated attacker to…
  • CVE-2026-12763 CVSS 4.2 medium IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to access another user's MCP server context due to improper…
  • CVE-2026-17628 CVSS 5.4 medium IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to change the password of an account due to improper…
  • CVE-2026-84889 CVSS 8.8 high IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of…
  • CVE-2026-81941 CVSS 8.8 high IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute arbitrary operating system commands on…
  • CVE-2026-81940 CVSS 8.8 high IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization…
  • CVE-2026-81268 CVSS 8.1 high IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute flows and obtain sensitive information due to…
  • CVE-2026-81265 CVSS 7.5 high IBM Langflow OSS 1.0.0 through 1.11.5.
  • CVE-2026-81213 CVSS 8.6 high IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to obtain sensitive information from internal network resources due to…
  • CVE-2026-81211 CVSS 8.8 high IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary Python code due to improper…
  • CVE-2026-81204 CVSS 9.8 critical IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary code due to code injection during graph…
  • CVE-2026-79742 CVSS 8.8 high IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an incomplete…
  • CVE-2026-79725 CVSS 6.5 medium IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to read arbitrary files due to improper access control.
  • CVE-2026-79724 CVSS 9.8 critical IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of…
  • CVE-2026-79723 CVSS 5.0 medium IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to obtain sensitive information due to improper…
  • CVE-2026-78575 CVSS 8.8 high IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation…
  • CVE-2026-78571 CVSS 8.8 high IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an unguarded eval()…
  • CVE-2026-78569 CVSS 8.8 high IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to execute arbitrary code due to an incomplete denylist in the…
  • CVE-2026-76059 CVSS 8.8 high IBM Langflow OSS 1.0.0 through 1.11.5 An attacker who could submit custom component source code could bypass the static security scanner…
  • CVE-2026-9225 CVSS 6.5 medium IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an authenticated attacker to access sensitive files belonging to other users…
  • CVE-2026-85025 CVSS 9.8 critical IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and access or modify chat…
  • CVE-2026-17631 CVSS 6.5 medium IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to a server-side…
  • CVE-2026-17627 CVSS 7.1 high IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information and inject messages into…
  • CVE-2026-17622 CVSS 6.5 medium IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to improper…
  • CVE-2026-17621 CVSS 5.4 medium IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote attacker to traverse directories on the system. An attacker could send a…
  • CVE-2026-14470 CVSS 6.5 medium IBM Langflow OSS 1.0.0 through 1.10.2 could allow an authenticated attacker to traverse directories on the system. An attacker could send…
  • CVE-2026-19306 CVSS 7.7 high IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files from the server filesystem — including…