Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-12940: IBM Langflow Remote Code Execution via Environment Variables

CVE-2026-12940 · published 1 month ago
Summary

IBM Langflow versions 1.0.0 to 1.10.1 are vulnerable to a serious security risk. An attacker can potentially execute code remotely on your system without needing a password. To protect yourself, update to the latest version of Langflow, which includes a fix for this vulnerability.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
ibm langflow oss <= 1.10.1
Original advisory text
IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launcher. The vulnerabili...
IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launcher. The vulnerability exists in src/lfx/src/lfx/base/mcp/util.py where the DANGEROUS_ENV_VARS blocklist fails to include SHELLOPTS , BASHOPTS , and PS4 environment variables.
Severity
9.8 Critical
CVSS 3.1: 9.8 (NVD)
CVSS 3.1: 9.8 (OSV)
Exploitation
EPSS <1%
Type
CWE-78OS Command Injection
Timeline
Published30 Jul 2026
Updated25 Sep 2026
First seen30 Jul 2026
Sources
CVE-2026-12940 · MITRE
Track software like this
Free during beta