Description
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary flows and access sensitive information due to improper authentication.
Published: 2026-08-28
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM Langflow OSS versions 1.0.0 through 1.11.1 contain a flaw that allows a remote attacker to bypass authentication controls, enabling the execution of arbitrary flows and the retrieval of sensitive information. The vulnerability stems from improper authentication handling and is related to CWE‑287. This could lead to unauthorized code execution or data exposure within the application.

Affected Systems

The impacted product is IBM Langflow OSS. Versions affected range from 1.0.0 up to and including 1.11.1. All installations of these releases are vulnerable until patched to 1.11.2.

Risk and Exploitability

With a CVSS score of 8.2 the vulnerability is considered high risk. The EPSS metric is not available, so the exploitation probability cannot be quantified, and it is not listed in the CISA KEV catalog. However, the flaw can be exploited remotely without authentication, and an attacker only needs access to the web interface to trigger unsupported flow execution. Because the attack vector is external, organizations should treat it with high urgency.

Generated by OpenCVE AI on August 28, 2026 at 23:24 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.11.2 https://pypi.org/project/langflow/


OpenCVE Recommended Actions

  • Upgrade IBM Langflow OSS to version 1.11.2 or later.
  • If an upgrade is not immediately feasible, restrict external access to the Langflow web interface and monitor for unauthorized flow execution attempts.
  • Ensure that authentication and authorization controls are correctly enforced, such as by validating user sessions before allowing flow execution.

Generated by OpenCVE AI on August 28, 2026 at 23:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Description IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary flows and access sensitive information due to improper authentication.
Title Langflow is affected by multiple authentication bypass, path traversal, authorization, and server-side request forgery vulnerabilities
First Time appeared Ibm
Ibm langflow Oss
Weaknesses CWE-287
CPEs cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:langflow_oss:1.11.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm langflow Oss
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Ibm Langflow Oss
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-28T20:51:27.834Z

Reserved: 2026-08-04T19:48:56.798Z

Link: CVE-2026-18891

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T22:16:46.990

Modified: 2026-08-28T22:16:46.990

Link: CVE-2026-18891

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T23:30:17Z

Weaknesses