Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.6
CVE-2026-12944: IBM Langflow OSS allows remote code execution as root
CVE-2026-12944 · published 11 days ago
Summary
The open‑source version of IBM Langflow (versions 1.0.0 to 1.10.0) can run any Python code that an attacker supplies, giving them full system rights on the server. This can be used to steal cloud credentials, copy files, or reach other services inside the container network. Apply the vendor’s update or restrict the component import feature until a patch is installed.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ibm | langflow oss | <= 1.10.0 |
Original advisory text
Incomplete Security Scanner Blocklist Enables Network-Based Code Execution
IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by submitting components containing socket or urllib imports. This enables: (1) AWS credential theft via IMDSv1 SSRF with full IAM role permissions, (2) arbitrary file exfiltration from the container filesystem, and (3) lateral movement to internal services (PostgreSQL, Redis) within the Docker network. The scanner incorrectly returns "validated": true, providing a false security signal.
Severity
9.6
Critical
CVSS 3.1: 9.6 (NVD)
Exploitation
EPSS <1%
Type
CWE-918Server-Side Request Forgery (SSRF)
Timeline
Published14 Sep 2026
Updated25 Sep 2026
First seen14 Sep 2026
Track software like this
Free during beta