Description
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary Python code due to improper authorization of custom components in stored flows.
Published: 2026-09-10
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

IBM Langflow OSS versions 1.0.0 through 1.11.5 allow a remote authenticated attacker to execute arbitrary Python code when adding or modifying custom components in stored flows. The improper authorization check bypasses user privileges, enabling full code execution on the host and compromising confidentiality, integrity, and availability. The weakness corresponds to CWE-862, an Authorization Bypass Through User-Controlled Input.

Affected Systems

The vulnerability affects IBM Langflow OSS, specifically all releases from 1.0.0 up through 1.11.5. The affected distribution is available through the Open Source Software (OSS) channel and includes the Python package langflow.

Risk and Exploitability

The CVSS score of 8.8 indicates a high‑severity risk. The EPSS score is not available, so current exploitation probability cannot be quantified from that metric. The vulnerability is not listed in the CISA KEV catalog. Attackers who are authenticated can upload a malicious flow containing custom component code and trigger execution on the target. The likely attack vector is via the web interface or API where authenticated users can create or edit flows.

Generated by OpenCVE AI on September 11, 2026 at 04:27 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.11.6 https://pypi.org/project/langflow/


OpenCVE Recommended Actions

  • Upgrade to IBM Langflow OSS version 1.11.6 or later, which removes the authorization flaw.
  • Disable or restrict the creation of custom component flows for non‑admin users.
  • Apply strict access controls so that only trusted administrators can modify flows.
  • Audit logs and monitor for abnormal flow creation or code execution events.

Generated by OpenCVE AI on September 11, 2026 at 04:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Langflow
Langflow langflow
CPEs cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*
Vendors & Products Langflow
Langflow langflow

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary Python code due to improper authorization of custom components in stored flows.
Title Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards
First Time appeared Ibm
Ibm langflow Oss
Weaknesses CWE-862
CPEs cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:langflow_oss:1.11.5:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm langflow Oss
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Langflow Oss
Langflow Langflow
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-12T03:55:46.308Z

Reserved: 2026-08-26T17:03:53.158Z

Link: CVE-2026-81211

cve-icon Vulnrichment

Updated: 2026-09-11T17:36:12.224Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-10T22:17:01.977

Modified: 2026-09-16T00:56:12.117

Link: CVE-2026-81211

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T07:15:16Z

Weaknesses