Description
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of command-line arguments in the MCP stdio server configuration.
Published: 2026-09-10
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

An authenticated attacker can exploit a lack of validation on command‑line arguments in the MCP stdio server configuration of IBM Langflow OSS to execute arbitrary OS commands. This flaw aligns with command injection weaknesses and can compromise confidentiality, integrity, and availability of the affected system.

Affected Systems

IBM Langflow OSS versions from 1.0.0 through 1.11.5 are affected. The issue is resolved in version 1.11.6, which IBM recommends installing without delay.

Risk and Exploitability

The vulnerability has a CVSS score of 8.8, indicating a high severity. The flaw is not listed in the known widespread exploitation. The likely attack vector requires remote authenticated access to the MCP stdio server, and an attacker could leverage the flaw to run arbitrary commands once authenticated.

Generated by OpenCVE AI on September 11, 2026 at 04:02 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.11.6 https://pypi.org/project/langflow/


OpenCVE Recommended Actions

  • Upgrade Langflow OSS to version 1.11.6 or newer.
  • If an upgrade is not immediately possible, restrict remove any unsanitized command‑line argument handling from the configuration.
  • Enforce strict input validation for any remaining command‑line parameters, allowing only explicitly whitelisted, safe values.

Generated by OpenCVE AI on September 11, 2026 at 04:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of command-line arguments in the MCP stdio server configuration.
Title Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards
First Time appeared Ibm
Ibm langflow Oss
Weaknesses CWE-78
CPEs cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:langflow_oss:1.11.5:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm langflow Oss
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Langflow Oss
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-11T14:38:55.406Z

Reserved: 2026-08-24T20:40:49.233Z

Link: CVE-2026-78575

cve-icon Vulnrichment

Updated: 2026-09-11T14:38:49.527Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-09-10T22:17:00.130

Modified: 2026-09-11T15:17:04.503

Link: CVE-2026-78575

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T07:30:09Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')