Description
IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute arbitrary system commands, and achieve full system compromise with Langflow service permissions.
Published: 2026-07-17
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM Langflow OSS versions 1.0.0 through 1.10.0 contain an arbitrary code execution flaw (CWE‑94). An attacker who can authenticate to the application can manipulate the database to elevate privileges to superuser, then launch arbitrary system commands with the application’s service permissions. This leads to full compromise of the host running the Langflow service.

Affected Systems

The vulnerability affects IBM Langflow OSS, specifically all releases from 1.0.0 up to and including 1.10.0.

Risk and Exploitability

The CVSS score for this issue is 9.9, indicating critical severity. The EPSS score is less than 1 %, meaning exploitation likelihood is low but still possible, especially in environments where database credentials are weak or exposed. The vulnerability is not listed in the CISA KEV catalog, so no known public exploits have been documented yet. The attack vector is inferred to be authenticated database manipulation within the application, allowing privileged escalation to superuser and subsequent execution of arbitrary system commands.

Generated by OpenCVE AI on July 30, 2026 at 23:48 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.10.1 https://pypi.org/project/langflow/


OpenCVE Recommended Actions

  • Upgrade IBM Langflow OSS to version 1.10.1 or later, which contains a fix for the privileged database manipulation flaw.
  • Reduce or eliminate superuser database privileges for normal application users and enforce least‑privilege database accounts.
  • Restrict authentication of the Langflow service to trusted networks or employees only, and enable multifactor authentication if supported to minimize the risk of credential compromise.

Generated by OpenCVE AI on July 30, 2026 at 23:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Description IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute arbitrary system commands, and achieve full system compromise with Langflow service permissions.
Title Arbitrary Code Execution in Python Interpreter Component
First Time appeared Ibm
Ibm langflow Oss
Weaknesses CWE-94
CPEs cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:langflow_oss:1.10.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm langflow Oss
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Ibm Langflow Oss
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-23T03:56:06.201Z

Reserved: 2026-05-14T19:17:56.124Z

Link: CVE-2026-8635

cve-icon Vulnrichment

Updated: 2026-07-21T01:57:39.072Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T00:00:06Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')