IBM Patches Multiple Langflow OSS Flaws Including Two Critical RCE Vulnerabilities
IBM patched 25 Langflow OSS flaws, including two unauthenticated critical remote code execution bugs, in version 1.12.3.
IBM disclosed 25 vulnerabilities in Langflow OSS affecting versions 1.0.0 through 1.12.2 and recommends upgrading to 1.12.3, with no workarounds. CVE-2026-104334 and CVE-2026-93674 are unauthenticated remote code execution flaws, each scored CVSS 9.8. Most other execution bugs require authentication and include sandbox escape, path traversal, unsafe caching, and dependency confusion. IBM reported no active exploitation, public exploits, or confirmed compromises; version 1.12.4 followed on September 29, 2026.