Description
IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arbitrary code on the host system, resulting in complete compromise
Severity (CVSS)
| Base score | 10 |
|---|---|
| Severity | Critical |
| Version | CVSS 3.1 |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| Provided by | CNA |
Weaknesses
- CWE-94 — CWE-94 Improper Control of Generation of Code ('Code Injection')
Affected products
| Vendor | Product | Versions |
|---|---|---|
| IBM | Langflow OSS | 1.0.0 to <=1.9.3 |
References
- https://www.ibm.com/support/pages/node/7277242 (vendor-advisory patch)
Generated from the official CVE List on 22 Jun 2026 14:43 UTC.