Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-79724: IBM Langflow OSS lets attackers run commands on server

CVE-2026-79724 · published 15 days ago
Summary

Versions 1.0.0 through 1.11.5 of IBM Langflow OSS can let a remote user send specially crafted input that makes the server run any command it wishes. This could let an attacker take control of the machine that hosts the software. Update to the latest released version and restrict network access to the service until the fix is applied.

What to do
  • Update langflow langflow to version 1.11.6 or later.
Affected software
VendorProductAffected versions
ibm langflow oss <= 1.11.5
langflow langflow >= 1.0.0, < 1.11.6
cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*
Original advisory text
Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.
Severity
9.8 Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-78OS Command Injection
Timeline
Published10 Sep 2026
Updated25 Sep 2026
First seen10 Sep 2026
Sources
CVE-2026-79724 · MITRE
Track software like this
Free during beta