Description
IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input code.
Published: 2026-07-30
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM Langflow OSS versions from 1.0.0 through 1.10.0 contain a flaw that allows an attacker to supply arbitrary code to the service. The vulnerability arises from an improper control of user‑provided input, enabling the execution of injected code with the privileges of the running instance. This flaw is classified as a code injection weakness (CWE‑94) and results in full compromise of the host system if exploited.

Affected Systems

The affected product is IBM Langflow OSS. Versions 1.0.0 through 1.10.0 are impacted as indicated by the vendor’s advisories and the listed CPE ranges. Versions beyond 1.10.0 are not known to be affected.

Risk and Exploitability

The CVSS score of 9.9 indicates a very high severity, while the EPSS score of less than 1% suggests that the probability of exploitation in the wild is currently low. The vulnerability is not yet listed in CISA’s KEV catalog. An attacker can likely exploit the flaw by sending malicious code to the Langflow OSS service over the network, which is then executed by the application process with its underlying permissions.

Generated by OpenCVE AI on August 3, 2026 at 10:33 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.10.1 https://pypi.org/project/langflow/


OpenCVE Recommended Actions

  • Upgrade IBM Langflow OSS to version 1.10.1, the first release that includes the fix
  • If an upgrade is not immediately possible, restrict network access to the Langflow OSS instance to trusted administrators or a secure internal network
  • Enforce strict input validation or disable execution of user supplied code within the application to mitigate injection risks

Generated by OpenCVE AI on August 3, 2026 at 10:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Description IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input code.
Title Remote Code Execution in CUGA Component CodeAgent
First Time appeared Ibm
Ibm langflow Oss
Weaknesses CWE-94
CPEs cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:langflow_oss:1.10.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm langflow Oss
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Ibm Langflow Oss
Langflow Langflow
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-31T03:56:19.395Z

Reserved: 2026-06-22T20:29:38.766Z

Link: CVE-2026-12946

cve-icon Vulnrichment

Updated: 2026-07-30T20:08:49.665Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T20:16:52.293

Modified: 2026-08-04T20:14:10.930

Link: CVE-2026-12946

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T10:45:03Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')