Description
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper control of code generation.
Published: 2026-10-07
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

IBM Langflow OSS contains an improper control of code generation flaw (CWE‑94) that can allow a remote authenticated attacker to execute arbitrary code. The vulnerability could enable the attacker to take full control of any host running the application, leading to loss of confidentiality, integrity, and availability, and the CVSS score of 8.8 reflects a high severity impact.

Affected Systems

The flaw exists in IBM Langflow OSS versions 1.0.0 through 1.12.2. All releases in that range expose the vulnerability; upgrading to 1.12.3 eliminates the issue.

Risk and Exploitability

The CVSS score of 8.8 indicates a serious risk. EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly documented exploits yet. However, the flaw requires the attacker to authenticate, after which malicious code can be supplied and executed with the application’s privileges. Because of the high impact and the requirements for authenticated access, organizations that rely on these versions should prioritize patching.

Generated by OpenCVE AI on October 7, 2026 at 01:54 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.12.3. https://pypi.org/project/langflow/#description


OpenCVE Recommended Actions

  • Update Langflow OSS to version 1.12.3 or later using pip.
  • If an upgrade cannot be performed immediately, temporarily disable or restrict authentication for code generation features to prevent privileged execution.
  • Continue to monitor for anomalous code execution activity and apply network segmentation or additional intrusion detection rules to limit potential lateral movement.

Generated by OpenCVE AI on October 7, 2026 at 01:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 00:30:00 +0000

Type Values Removed Values Added
Description IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper control of code generation.
Title Langflow OSS is affected by multiple vulnerabilities
First Time appeared Ibm
Ibm langflow Oss
Weaknesses CWE-94
CPEs cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:langflow_oss:1.12.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm langflow Oss
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Langflow Oss
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-10-07T00:02:53.758Z

Reserved: 2026-09-10T15:46:14.799Z

Link: CVE-2026-88962

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T01:16:34.377

Modified: 2026-10-07T01:16:34.377

Link: CVE-2026-88962

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T04:00:09Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')