ZeroHour

CVE-2026-18729

large

Authenticated RCE via Code Injection in IBM Langflow OSS 1.0.0–1.11.1

CVSS 3.1
8.8 high
EPSS
<1%p40
Published
()
Modified
AI analysis

IBM Langflow OSS versions 1.0.0 through 1.11.1 contain a code-generation flaw (CWE-94, improper control of generated code) that allows remote code execution. An attacker who already holds low-privileged, authenticated access to a Langflow instance can send crafted input that is incorporated into dynamically generated code, which the server then executes. Successful exploitation yields arbitrary code execution on the host running Langflow, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.8). All self-hosted Langflow OSS deployments running versions 1.0.0 through 1.11.1 are affected. Exploitation has not been confirmed: there is no known public proof of concept, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at about 0.5% (40th percentile).

What to do: Upgrade all Langflow OSS deployments to the latest fixed release beyond version 1.11.1. Because the flaw requires authenticated access, review which accounts can reach Langflow instances — especially any exposed to the internet — and restrict access to trusted users or bind the service to internal networks until patched. Check logs for low-privileged accounts that could be leveraged to submit crafted inputs.

Affected
IBM Langflow OSS1.0.0 through 1.11.1 (inclusive)
Estimated exposure
large≈10,000–100,000 self-hosted instances, of which tens of thousands are internet-exposed — Public internet-wide scans during 2025 disclosed tens of thousands of internet-exposed Langflow servers, and total self-hosted deployments (including Docker-based and internal installs) are plausibly an order of magnitude higher, though…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitrary code due to improper control of generation of code.

Vendors
langflow
Products
langflow
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.