Description
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command ('Code Injection'), aka improper control of code generation.
Published: 2026-10-06
Score: 8.1 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Patch Now
AI Analysis

Impact

IBM Langflow OSS versions 1.0.0 through 1.12.2 suffer from an OS command injection flaw (CWE‑94). When an authenticated user supplies specially crafted input, the application fails to neutralize special elements, enabling execution of arbitrary operating‑system commands. This gives a remote attacker the full platform‑level capabilities of the machine hosting the application, potentially compromising confidentiality, integrity, and availability.

Affected Systems

IBM Langflow OSS (open‑source edition) is affected in versions 1.0.0 to 1.12.2. The security advisory recommends upgrading to version 1.12.3 or later to remediate the flaw. Users running earlier releases are at risk.

Risk and Exploitability

With a CVSS score of 8.1 the vulnerability is classified as High severity. No EPSS score is currently published, so exploitation probability cannot be quantified. It is not listed in CISA KEV, suggesting no known widespread exploitation yet. The flaw requires that the attacker already have authenticated access to the application, but once authenticated they can run arbitrary OS commands. Attackers can lever this to elevate privileges, compromise the host, or pivot to other systems. No additional conditions are listed, implying that the presence of standard user credentials is sufficient for exploitation.

Generated by OpenCVE AI on October 7, 2026 at 01:37 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.12.3. https://pypi.org/project/langflow/#description


OpenCVE Recommended Actions

  • Upgrade IBM Langflow OSS to version 1.12.3 or later.
  • Restrict authenticated user accounts to administrators and enforce least privilege policies.
  • Monitor execution logs for abnormal command usage and disable command‑generation features until the patch is applied.

Generated by OpenCVE AI on October 7, 2026 at 01:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 00:30:00 +0000

Type Values Removed Values Added
Description IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command ('Code Injection'), aka improper control of code generation.
Title Langflow OSS is affected by multiple vulnerabilities
First Time appeared Ibm
Ibm langflow Oss
Weaknesses CWE-94
CPEs cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:langflow_oss:1.12.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm langflow Oss
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Ibm Langflow Oss
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-10-06T23:59:56.989Z

Reserved: 2026-09-24T20:36:43.258Z

Link: CVE-2026-97674

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T01:16:36.247

Modified: 2026-10-07T01:16:36.247

Link: CVE-2026-97674

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T01:45:08Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')