Description
IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on the server without any credentials via 2 HTTP requests.
Published: 2026-08-05
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows an attacker to execute arbitrary code on a Langflow OSS server by leveraging the component generation, validation, and custom component handling logic. The flaw is triggered through two HTTP requests and does not require any authentication, meaning anyone on the internet can abuse it. As a result, an attacker could run arbitrary programs, modify data, or take full control of the affected system, compromising confidentiality, integrity, and availability.

Affected Systems

The flaw affects IBM Langflow OSS from version 1.0.0 up to and including 1.10.3. Users running these releases – the open‑source edition of Langflow – are at risk and should confirm whether their deployment falls within this range.

Risk and Exploitability

With a CVSS score of 8.8, the vulnerability is considered high severity. The EPSS score is not available, so the current exploit likelihood cannot be quantified, but the attack conditions are simple – any remote user can craft the required HTTP traffic – and the flaw is listed as not in the CISA KEV catalog. Attack can exploit the server from outside, gaining full execution privileges, and can carry out the exploit with no prior access or credentials. The ease of exploitation and broad access scope make this a high‑risk threat.

Generated by OpenCVE AI on August 5, 2026 at 20:35 UTC.

Remediation

Vendor Solution

IBM recommends upgrading to Langflow OSS 1.11.0 or newer https://github.com/langflow-ai/langflow/releases


OpenCVE Recommended Actions

  • Upgrade Langflow OSS to version 1.11.0 or newer to remove the vulnerability.
  • Restrict external network access to the server by limiting the service to trusted IP ranges or by placing a firewall or reverse proxy that requires authentication.
  • As an interim measure, disable or restrict the component generation, validation, and custom component handling endpoints if possible, ensuring no public access is available until the upgrade can be applied.

Generated by OpenCVE AI on August 5, 2026 at 20:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Description IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on the server without any credentials via 2 HTTP requests.
Title Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling
First Time appeared Ibm
Ibm langflow Oss
Weaknesses CWE-94
CPEs cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:langflow_oss:1.10.3:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm langflow Oss
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Langflow Oss
Langflow Langflow
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-06T03:55:56.048Z

Reserved: 2026-05-08T17:42:00.508Z

Link: CVE-2026-8182

cve-icon Vulnrichment

Updated: 2026-08-05T19:26:08.966Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-05T19:17:43.823

Modified: 2026-08-06T18:56:32.420

Link: CVE-2026-8182

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T20:45:05Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')