Description
IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by submitting components containing socket or urllib imports. This enables: (1) AWS credential theft via IMDSv1 SSRF with full IAM role permissions, (2) arbitrary file exfiltration from the container filesystem, and (3) lateral movement to internal services (PostgreSQL, Redis) within the Docker network. The scanner incorrectly returns "validated": true, providing a false security signal.
Published: 2026-09-14
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

IBM Langflow OSS versions 1.0.0 through 1.10.0 allow attackers to submit malicious components that import socket or urllib, which the security scanner incorrectly marks as "validated": true. Based on the description, it is inferred that the flaw involves a reflected outbound request (CWE-918) that leads to arbitrary Python code execution with root privileges on the host. As a result, an adversary can steal AWS credentials via IMDSv1 SSRF, exfiltrate files from the container file system, or pivot to internal services such as PostgreSQL and Redis.

Affected Systems

IBM Langflow OSS, versions 1.0.0 up to and including 1.10.0, is the only product affected according to CNA data.

Risk and Exploitability

The vulnerability carries a CVSS score of 9.6, indicating a critical severity. The EPSS score is <1%, reflecting a very low but nonzero probability of exploitation. Although the KEV catalog does not list it, the impact—root-level code execution and lateral movement—requires immediate attention. Attackers can exploit this via network-based submission of malicious components, elevating the risk for all exposed Langflow instances.

Generated by OpenCVE AI on September 17, 2026 at 19:14 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.10.1 https://pypi.org/project/langflow/


OpenCVE Recommended Actions

  • Upgrade IBM Langflow OSS to version 1.10.1 or later, as per IBM’s official recommendation.
  • Restrict component upload functionality to privileged, authenticated users only to prevent unauthorized malicious submissions.
  • Reconfigure the security scanner so that it rejects or flags components containing socket or urllib imports, and document the scanner adjustments for audit purposes.

Generated by OpenCVE AI on September 17, 2026 at 19:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by submitting components containing socket or urllib imports. This enables: (1) AWS credential theft via IMDSv1 SSRF with full IAM role permissions, (2) arbitrary file exfiltration from the container filesystem, and (3) lateral movement to internal services (PostgreSQL, Redis) within the Docker network. The scanner incorrectly returns "validated": true, providing a false security signal.
Title Incomplete Security Scanner Blocklist Enables Network-Based Code Execution
First Time appeared Ibm
Ibm langflow Oss
Weaknesses CWE-918
CPEs cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:langflow_oss:1.10.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm langflow Oss
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Ibm Langflow Oss
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-16T03:56:13.581Z

Reserved: 2026-06-22T19:58:17.706Z

Link: CVE-2026-12944

cve-icon Vulnrichment

Updated: 2026-09-15T17:45:48.736Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T22:16:56.950

Modified: 2026-09-16T19:21:55.793

Link: CVE-2026-12944

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:45:16Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)