Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-81204: Langflow can let attackers run code remotely

CVE-2026-81204 · published 15 days ago
Summary

Versions 1.0.0 through 1.11.5 of IBM Langflow OSS let a remote attacker insert malicious code while building a workflow, which could then be executed on the server. This could give the attacker control over the system hosting Langflow. Upgrade to the latest Langflow release or apply the vendor's security patches to close the gap.

What to do
  • Update langflow langflow to version 1.11.6 or later.
Affected software
VendorProductAffected versions
ibm langflow oss <= 1.11.5
langflow langflow >= 1.0.0, < 1.11.6
cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*
Original advisory text
Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary code due to code injection during graph construction.
Severity
9.8 Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-94Code Injection
Timeline
Published10 Sep 2026
Updated25 Sep 2026
First seen10 Sep 2026
Sources
CVE-2026-81204 · MITRE
Track software like this
Free during beta