Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-9198: IBM Langflow allows attackers to run code on default installations

CVE-2026-9198 · published 2 months ago · actively exploited
Summary

IBM Langflow's default settings allow unauthorized users to run code on the system, posing a significant risk. This issue affects versions 1.0.0 through 1.10.0 of the software. To protect your system, update to a fixed version or apply a patch as soon as possible.

What to do
  • Update langflow langflow to version 1.10.1 or later.
Affected software
VendorProductAffected versions
ibm langflow All versions
ibm langflow oss <= 1.10.0
langflow langflow >= 1.0.0, < 1.10.1
cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*
Original advisory text
IBM Langflow Code Injection Vulnerability
Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.
Severity
9.8 Critical
CVSS 3.1: 9.8 (MITRE)
CVSS 3.1: 9.8 (OSV)
Exploitation
Known exploited
Listed in the CISA KEV catalogue - exploitation confirmed in the wild.
EPSS 29%
Type
CWE-94Code Injection
Timeline
Published17 Jul 2026
Updated25 Sep 2026
First seen17 Jul 2026
Sources
CVE-2026-9198 · OSV
CVE-2026-9198 · NVD
CVE-2026-9198 · MITRE
CVE-2026-9198 · CISA KEV
Track software like this
Free during beta