Description
IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute arbitrary operating system commands on the server at the privilege level of the application process by constructing a flow with an MCP Tools component configured to use a local stdio subprocess transport. This bypasses both the LANGFLOW_CUSTOM_COMPONENT_ADMIN_ONLY and LANGFLOW_BLOCK_CODE_INTERPRETER_COMPONENTS server-side controls intended to prevent exactly this class of access. Successful exploitation could lead to arbitrary command execution, sensitive data exposure (including credentials from the process environment), file system modification, and lateral movement to services reachable from the server.
Published: 2026-09-10
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary Code Execution
Action: Patch Now
AI Analysis

Impact

An authenticated non‑administrative user can construct a flow that includes an MCP Tools component configured with a local stdio subprocess transport, bypassing the Langflow server‑side controls designed to restrain such execution. This flaw gives the attacker the ability to run arbitrary operating system commands at the privileges of the application process, exposing sensitive data such as environment credentials, modifying the file system, and enabling lateral movement to other services on the host.

Affected Systems

IBM Langflow OSS, versions 1.0.0 through 1.11.5 are vulnerable. The patched release is 1.11.6.

Risk and Exploitability

The CVSS score of 8.8 classifies this vulnerability as high severity. EPSS data is not provided, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires authentication as a non‑administrative user, so the attack vector is internal. Once authenticated, the attacker can execute arbitrary commands on the host, compromising integrity and availability.

Generated by OpenCVE AI on September 11, 2026 at 04:27 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.11.6 https://pypi.org/project/langflow/


OpenCVE Recommended Actions

  • Apply the IBM‑released Langflow OSS 1.11.6 or later, available via PyPI to replace the vulnerable version.
  • If a patch cannot be applied immediately, reconfigure the application so that only administrators can create flows containing the MCP Tools component or disable that component entirely in the configuration.
  • Run the Langflow service under a minimal‑privilege system account to limit the potential impact of any successful exploitation.

Generated by OpenCVE AI on September 11, 2026 at 04:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Langflow
Langflow langflow
CPEs cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*
Vendors & Products Langflow
Langflow langflow

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute arbitrary operating system commands on the server at the privilege level of the application process by constructing a flow with an MCP Tools component configured to use a local stdio subprocess transport. This bypasses both the LANGFLOW_CUSTOM_COMPONENT_ADMIN_ONLY and LANGFLOW_BLOCK_CODE_INTERPRETER_COMPONENTS server-side controls intended to prevent exactly this class of access. Successful exploitation could lead to arbitrary command execution, sensitive data exposure (including credentials from the process environment), file system modification, and lateral movement to services reachable from the server.
Title Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards
First Time appeared Ibm
Ibm langflow Oss
Weaknesses CWE-284
CPEs cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:langflow_oss:1.11.5:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm langflow Oss
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Langflow Oss
Langflow Langflow
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-12T03:55:47.362Z

Reserved: 2026-08-27T20:19:07.391Z

Link: CVE-2026-81941

cve-icon Vulnrichment

Updated: 2026-09-11T17:37:36.931Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-10T22:17:03.220

Modified: 2026-09-16T00:59:19.183

Link: CVE-2026-81941

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T09:00:10Z

Weaknesses