Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-9198: IBM Langflow allows attackers to run code on default installations

CVE-2026-9198 CVE-2026-9198
Summary

IBM Langflow's default settings allow unauthorized users to run code on the system, posing a significant risk. This issue affects versions 1.0.0 through 1.10.0 of the software. To protect your system, update to a fixed version or apply a patch as soon as possible.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
ibm langflow oss <= 1.10.0
Original title
IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via ...
Original description
IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments
mitre CVSS3.1 9.8
Vulnerability type
CWE-94 Code Injection
Published: 17 Jul 2026 · Updated: 18 Jul 2026 · First seen: 17 Jul 2026