Description
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper input validation.
Published: 2026-10-06
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from improper input validation, which allows a remote authenticated user to execute arbitrary code on the server. Attackers can inject malicious payloads that are misinterpreted by the application and result in code execution. The type of weakness corresponds to CWE-693, indicating a failure to enforce adequate protection mechanisms.

Affected Systems

IBM Langflow OSS versions 1.0.0 through 1.12.2 are impacted. System administrators should verify whether their deployments run any of these releases and prepare to deploy the fixed release 1.12.3 or later.

Risk and Exploitability

With a CVSS score of 8.8, the severity is high. No EPSS score is available, and the vulnerability is not listed in CISA KEV, suggesting no confirmed widespread exploitation yet. However, because the flaw requires remote authentication, attackers who can obtain or guess valid credentials can leverage the vulnerability. Administrators should assume the risk of a successful exploit until the patch is applied.

Generated by OpenCVE AI on October 7, 2026 at 01:38 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.12.3. https://pypi.org/project/langflow/#description


OpenCVE Recommended Actions

  • Apply an upgrade to IBM Langflow OSS version 1.12.3 or later
  • If an upgrade cannot be performed immediately, restrict access to the application to trusted administrators only and block all other inbound traffic until the patch is applied
  • After patch or restriction, monitor system logs for anomalous execution attempts and enforce strict access controls, including multi‑factor authentication

Generated by OpenCVE AI on October 7, 2026 at 01:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 00:30:00 +0000

Type Values Removed Values Added
Description IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper input validation.
Title Langflow OSS is affected by multiple vulnerabilities
First Time appeared Ibm
Ibm langflow Oss
Weaknesses CWE-693
CPEs cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:langflow_oss:1.12.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm langflow Oss
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Langflow Oss
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-10-06T23:59:43.554Z

Reserved: 2026-09-24T20:48:57.818Z

Link: CVE-2026-97678

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T01:16:36.517

Modified: 2026-10-07T01:16:36.517

Link: CVE-2026-97678

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T01:45:08Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure