Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-7873: IBM Langflow OSS: Authenticated Attackers Can Execute Commands

CVE-2026-7873
Summary

IBM Langflow OSS versions 1.0.0 through 1.10.0 have a security flaw that lets anyone with a valid account run any system command and access sensitive information like passwords. This means an attacker could gain full control of the system and move to other parts of the network. To stay secure, update to a fixed version of IBM Langflow OSS as soon as possible.

Original title
IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated attackers to execute arbitrary OS commands and read sensitive files including credentials, enabling complete system compromise and lateral...
Original description
IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated attackers to execute arbitrary OS commands and read sensitive files including credentials, enabling complete system compromise and lateral movement.
nvd CVSS3.1 9.9
Vulnerability type
CWE-94 Code Injection
Published: 30 Jun 2026 · Updated: 20 Jul 2026 · First seen: 30 Jun 2026