Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-9198: IBM Langflow allows attackers to run code on default installations
CVE-2026-9198
CVE-2026-9198
Summary
IBM Langflow's default settings allow unauthorized users to run code on the system, posing a significant risk. This issue affects versions 1.0.0 through 1.10.0 of the software. To protect your system, update to a fixed version or apply a patch as soon as possible.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ibm | langflow oss | <= 1.10.0 |
Original title
IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via ...
Original description
IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments
mitre CVSS3.1
9.8
Vulnerability type
CWE-94
Code Injection
- https://www.ibm.com/support/pages/node/7278927 vendor-advisory patch
Published: 17 Jul 2026 · Updated: 18 Jul 2026 · First seen: 17 Jul 2026