Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-79724: IBM Langflow OSS lets attackers run commands on server
CVE-2026-79724 · published 15 days ago
Summary
Versions 1.0.0 through 1.11.5 of IBM Langflow OSS can let a remote user send specially crafted input that makes the server run any command it wishes. This could let an attacker take control of the machine that hosts the software. Update to the latest released version and restrict network access to the service until the fix is applied.
What to do
- Update langflow langflow to version 1.11.6 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ibm | langflow oss | <= 1.11.5 |
| langflow | langflow |
>= 1.0.0, < 1.11.6 cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:* |
Original advisory text
Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.
References
- https://www.ibm.com/support/pages/node/7286666 Vendor Advisory
Severity
9.8
Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-78OS Command Injection
Timeline
Published10 Sep 2026
Updated25 Sep 2026
First seen10 Sep 2026
Track software like this
Free during beta