Description
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to an incomplete blocklist in the code security scanner.
Published: 2026-10-06
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

An incomplete blocklist in IBM Langflow OSS’s code security scanner allows a malicious actor to inject and execute arbitrary code. The flaw can be exploited to run code with the privileges of the application, granting full control over the host environment, compromising data integrity and confidentiality, and potentially allowing further lateral movement within the network. The underlying weakness is a code injection problem identified as CWE‑94.

Affected Systems

IBM Langflow OSS versions 1.0.0 through 1.12.2 are vulnerable. Upgrading to version 1.12.3 removes the flaw, as released by IBM. The affected products are under the IBM vendor name and the OS‑agnostic Langflow OSS component.

Risk and Exploitability

The CVSS score of 8.8 classifies the vulnerability as high severity. While the EPSS score is not available, the lack of a KEV listing suggests no publicly known exploits yet; however, the nature of the flaw implies a remote code execution attack vector that could be accessed through any exposed API or interface that triggers the scanner. Based on the description, the likely attack vector is remote, and an attacker could possibly trigger the injection by sending specially crafted input to the application.

Generated by OpenCVE AI on October 7, 2026 at 01:39 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.12.3. https://pypi.org/project/langflow/#description


OpenCVE Recommended Actions

  • Upgrade IBM Langflow OSS to version 1.12.3 as soon as possible to eliminate the code injection flaw.
  • Remove or hard‑code any custom handler or plugin that may bypass the blocklist, and audit the application’s configuration to ensure only trusted code paths are allowed.
  • Implement monitoring for anomalous process creation or shell activity originating from the Langflow application to detect potential bypass attempts during the transition period.

Generated by OpenCVE AI on October 7, 2026 at 01:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 00:30:00 +0000

Type Values Removed Values Added
Description IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to an incomplete blocklist in the code security scanner.
Title Langflow OSS is affected by multiple vulnerabilities
First Time appeared Ibm
Ibm langflow Oss
Weaknesses CWE-94
CPEs cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:langflow_oss:1.12.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm langflow Oss
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Langflow Oss
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-10-06T23:59:07.370Z

Reserved: 2026-09-24T19:25:15.513Z

Link: CVE-2026-97655

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T01:16:35.833

Modified: 2026-10-07T01:16:35.833

Link: CVE-2026-97655

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T01:45:08Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')