Description
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in code, resulting in a sandbox escape.
Published: 2026-10-06
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Upgrade
AI Analysis

Impact

IBM Langflow OSS between versions 1.0.0 and 1.12.2 contains an injection flaw that allows a remote authenticated attacker to execute arbitrary code. The vulnerability arises from improper neutralization of special elements in code that are interpreted by the runtime, leading to a sandbox escape. Because of this flaw a malicious user can compromise the entire system and gain full control, representing a high‑confidence remote code execution risk consistent with CWE‑94.

Affected Systems

Affected systems are IBM Langflow OSS installations running any of the versions listed from 1.0.0 up to 1.12.2 inclusive. The product includes the open source stack that is widely used for workflow orchestration. The only version that includes the fix is 1.12.3, which was released after the identified issue was published.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity impact, yet the EPSS score is not available so exact exploitation likelihood cannot be measured. Since the flaw requires the attacker to be authenticated, the attack vector is remote but limited to users who already have valid credentials. The issue is not present in the CISA KEV list, but it should still be treated as critical given the remote code execution potential. Organizations should act immediately to apply the fix or otherwise mitigate the risk.

Generated by OpenCVE AI on October 7, 2026 at 01:40 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.12.3. https://pypi.org/project/langflow/#description


OpenCVE Recommended Actions

  • Update Langflow OSS to version 1.12.3 or later to apply the vendor patch.
  • If an upgrade is not yet possible, enforce stringent access controls and monitor the authentication logs for suspicious activity that might indicate exploitation attempts.
  • Deploy an intrusion detection or file integrity monitoring solution to detect unauthorized code execution or changes to critical application files during the interim period.

Generated by OpenCVE AI on October 7, 2026 at 01:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 00:30:00 +0000

Type Values Removed Values Added
Description IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in code, resulting in a sandbox escape.
Title Langflow OSS is affected by multiple vulnerabilities
First Time appeared Ibm
Ibm langflow Oss
Weaknesses CWE-94
CPEs cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:langflow_oss:1.12.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm langflow Oss
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Langflow Oss
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-10-06T23:58:57.606Z

Reserved: 2026-09-24T20:42:27.775Z

Link: CVE-2026-97676

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T01:16:36.387

Modified: 2026-10-07T01:16:36.387

Link: CVE-2026-97676

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T01:45:08Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')