Description
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper control of code generation.
Published: 2026-10-07
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows an authenticated attacker to execute arbitrary code by exploiting improper control of code generation; this is a classic example of CWE‑94 and can lead to complete compromise of the running system.

Affected Systems

IBM Langflow OSS versions 1.0.0 through 1.12.2 are affected by this flaw; upgrading to version 1.12.3 or later removes the vulnerability.

Risk and Exploitability

The issue carries a CVSS score of 8.5, indicating high severity, and no EPSS value is available. It is not listed in CISA KEV. The threat requires an authenticated user to trigger the code generation feature, implying a remote code execution scenario that could be abused by attackers who gain legitimate or stolen credentials. Organizations should treat this as a high‑risk vulnerability and act promptly.

Generated by OpenCVE AI on October 7, 2026 at 01:33 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.12.3. https://pypi.org/project/langflow/#description


OpenCVE Recommended Actions

  • Update Langflow OSS to version 1.12.3 or later.
  • If an upgrade is not immediately possible, restrict code generation functionality or revoke the permissions that allow authenticated users to invoke it.
  • Continuously monitor logs for abnormal code execution activity and apply any new security updates as they become available.

Generated by OpenCVE AI on October 7, 2026 at 01:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 00:30:00 +0000

Type Values Removed Values Added
Description IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper control of code generation.
Title Langflow OSS is affected by multiple vulnerabilities
First Time appeared Ibm
Ibm langflow Oss
Weaknesses CWE-94
CPEs cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:langflow_oss:1.12.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm langflow Oss
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Ibm Langflow Oss
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-10-07T00:02:05.322Z

Reserved: 2026-09-17T22:41:37.626Z

Link: CVE-2026-93449

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T01:16:35.057

Modified: 2026-10-07T01:16:35.057

Link: CVE-2026-93449

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T04:15:11Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')