Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-13448: Langflow: Unauthenticated Remote Code Execution and Denial of Service
CVE-2026-13448 · published 2 months ago
Summary
Langflow's public API has unauthenticated endpoints that can be exploited for remote code execution and denial of service attacks. This means an attacker could potentially take control of your system or make it unavailable to users. Update to the latest version of Langflow to fix these vulnerabilities.
What to do
- Update langflow langflow to version 1.10.2 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ibm | langflow oss | <= 1.10.1 |
| langflow | langflow |
>= 1.0.0, < 1.10.2 cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:* |
Original advisory text
IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution vulnerability in the public flow build endpoint ( /api/v1/build_public_tmp/{flow_id}/flow ). The ...
IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution vulnerability in the public flow build endpoint ( /api/v1/build_public_tmp/{flow_id}/flow ). The vulnerability stems from an incomplete denylist in the validate_public_flow_no_code_execution() function that fails to block several code-execution agent components including OpenDsStarAgent, CodeActAgentSmolagents, and CSVAgent.
Severity
9.8
Critical
CVSS 3.1: 8.1 (NVD)
Exploitation
EPSS <1%
Type
CWE-184Incomplete List of Disallowed Inputs
Timeline
Published17 Jul 2026
Updated25 Sep 2026
First seen17 Jul 2026
Track software like this
Free during beta