Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-93675: IBM Langflow OSS allows remote code execution
CVE-2026-93675 · published 4 days ago
Summary
Versions 1.0.0 through 1.12.2 of IBM Langflow OSS can be tricked into loading malicious code, letting an attacker run commands on the server. This could let an outsider take control of the system or steal data. Upgrade to a newer, patched version or apply the vendor's recommended mitigation as soon as possible.
What to do
- Update langflow langflow to version 1.12.3 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ibm | langflow oss | <= 1.12.2 |
| langflow | langflow |
>= 1.0.0, < 1.12.3 cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:* |
Original advisory text
Langflow OSS is affected by multiple vulnerabilities
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to an expected dependency confusion.
References
- https://www.ibm.com/support/pages/node/7290694 Vendor Advisory
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
9.8
Critical
Type
CWE-440Expected Behavior Violation
Timeline
Published7 Oct 2026
Updated10 Oct 2026
First seen7 Oct 2026
Track software like this
Free during beta