Description
IBM Langflow OSS 1.0.0 through 1.12.2 could allow an attacker with access to the server secret and Redis write access to submit a malicious serialized cache value. When the value was retrieved, deserialization could have executed attacker-controlled code with the privileges of the service process.
Published: 2026-10-07
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

IBM Langflow OSS is vulnerable to deserialization of untrusted data. An attacker who can write to the Redis cache and who knows the server secret can place a malicious serialized value. When the service later retrieves this value, deserialization executes attacker‑controlled code with the privileges of the service process, resulting in full remote code execution. The flaw directly compromises confidentiality, integrity, and availability of the system.

Affected Systems

The affected product is IBM Langflow OSS versions 1.0.0 through 1.12.2. IBM recommends upgrading to version 1.12.3 or later to eliminate the issue.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity. Although the EPSS score is not available, the lack of listing in CISA KEV does not diminish the potential impact, especially given the required conditions of a server secret and Redis write permission. The attack vector is likely to be internal or authenticated remote, and an attacker with those privileges can achieve arbitrary code execution on the host.

Generated by OpenCVE AI on October 7, 2026 at 01:34 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.12.3. https://pypi.org/project/langflow/#description


OpenCVE Recommended Actions

  • Upgrade IBM Langflow OSS to version 1.12.3 or later.
  • Sequester the Redis cache write access to only trusted components and ensure that the server secret is stored in a protected environment (e.g., a secrets manager).
  • Implement strict validation or avoid deserialization of data from Redis; refactor the application to use safe serialization formats or disable the vulnerable functionality until a patch is applied.

Generated by OpenCVE AI on October 7, 2026 at 01:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 00:30:00 +0000

Type Values Removed Values Added
Description IBM Langflow OSS 1.0.0 through 1.12.2 could allow an attacker with access to the server secret and Redis write access to submit a malicious serialized cache value. When the value was retrieved, deserialization could have executed attacker-controlled code with the privileges of the service process.
Title Langflow OSS is affected by multiple vulnerabilities
First Time appeared Ibm
Ibm langflow Oss
Weaknesses CWE-502
CPEs cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:langflow_oss:1.12.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm langflow Oss
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Langflow Oss
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-10-07T00:01:39.959Z

Reserved: 2026-09-17T22:30:56.608Z

Link: CVE-2026-93447

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T01:16:34.787

Modified: 2026-10-07T01:16:34.787

Link: CVE-2026-93447

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T04:00:09Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data