Description
IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox implementation.
Published: 2026-07-30
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper input validation flaw in IBM Langflow OSS 1.0.0 through 1.10.1’s PythonREPL sandbox implementation. Based on the description, it is inferred that the flaw allows an attacker to bypass the sandbox and execute arbitrary code, which can be used to read or exfiltrate sensitive data stored on the system. The weakness is classified as CWE‑94, indicating a code injection issue that compromises confidentiality.

Affected Systems

IBM Langflow OSS, versions 1.0.0 through 1.10.1 are affected.

Risk and Exploitability

The CVSS score of 9.9 denotes a critical level of risk. The EPSS score of < 1% indicates a very low but nonzero exploitation probability, yet the lack of mitigation and the high CVSS suggest that if an attack vector is usable, exploitation is likely. The vulnerability is not listed in CISA’s KEV catalog, yet the severity warrants caution. Based on the description, it is inferred that the likely attack vector is the input to the PythonREPL feature, most plausibly supplied via the application’s API or web interface; the attacker would need to provide malicious code that bypasses sandbox controls, leading to data exposure.

Generated by OpenCVE AI on August 4, 2026 at 11:43 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.10.2 https://pypi.org/project/langflow/


OpenCVE Recommended Actions

  • Upgrade IBM Langflow OSS to version 1.10.2 or later
  • If an upgrade cannot be performed immediately, disable or restrict access to the PythonREPL sandbox feature to prevent untrusted input
  • Audit configuration files and code to ensure no legacy PythonREPL sandbox implementations are still active

Generated by OpenCVE AI on August 4, 2026 at 11:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Description IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox implementation.
Title Python Interpreter Sandbox Bypass Leading to Sensitive Data Exposure
First Time appeared Ibm
Ibm langflow Oss
Weaknesses CWE-94
CPEs cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:langflow_oss:1.10.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm langflow Oss
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Ibm Langflow Oss
Langflow Langflow
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-31T03:56:17.304Z

Reserved: 2026-06-26T15:01:44.178Z

Link: CVE-2026-13435

cve-icon Vulnrichment

Updated: 2026-07-30T18:04:50.511Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T19:17:06.840

Modified: 2026-08-04T20:15:08.537

Link: CVE-2026-13435

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T11:45:03Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')