Description
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command ('Code Injection') related to improper input validation.
Published: 2026-10-06
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

IBM’s Langflow OSS contains a code injection flaw caused by improper neutralization of special elements used in an OS command. An attacker with valid credentials can supply crafted input that is passed directly to the operating system, allowing arbitrary code execution on the host system. The vulnerability originates from insufficient input validation and results in high impact on confidentiality, integrity, and availability of the affected systems.

Affected Systems

The flaw is present in IBM Langflow OSS versions 1.0.0 through 1.12.2, including the 1.12.2 release. All installations of these versions that expose endpoints or interfaces capable of evaluating user‑supplied data for OS command construction are affected. Upgrading to the released 1.12.3 release removes the vulnerability.

Risk and Exploitability

The CVSS score of 8.8 categorizes this as a high‑severity issue. The EPSS score is not available, but the lack of public exploitation reports does not diminish the potential for use by a skilled adversary who has access to authenticated accounts. Because the vulnerability requires authentication, internal actors or compromised credentials pose a significant risk. The vulnerability is not listed in CISA’s KEV catalog, but the high severity and the nature of the flaw warrant urgent remediation.

Generated by OpenCVE AI on October 7, 2026 at 01:38 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.12.3. https://pypi.org/project/langflow/#description


OpenCVE Recommended Actions

  • Upgrade IBM Langflow OSS to version 1.12.3 or later to eliminate the code injection flaw.
  • If an immediate upgrade is not possible, disable or tightly restrict the feature that invokes OS commands with user input until the patch is applied.
  • Implement monitoring of system logs for anomalous command execution and enforce least‑privilege access controls to limit the surfaces exposed to authenticated users.

Generated by OpenCVE AI on October 7, 2026 at 01:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 00:30:00 +0000

Type Values Removed Values Added
Description IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command ('Code Injection') related to improper input validation.
Title Langflow OSS is affected by multiple vulnerabilities
First Time appeared Ibm
Ibm langflow Oss
Weaknesses CWE-94
CPEs cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:langflow_oss:1.12.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm langflow Oss
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Langflow Oss
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-10-06T23:59:33.248Z

Reserved: 2026-09-24T20:50:04.126Z

Link: CVE-2026-97679

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T01:16:36.643

Modified: 2026-10-07T01:16:36.643

Link: CVE-2026-97679

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T01:45:08Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')