ZeroHour

CVE-2026-7524

CVSS 3.1
9.8 critical
EPSS
<1%p54
Published
()
Modified
Description

IBM Langflow OSS 1.0.0 through 1.9.1 could allow remote code execution due to improper validation of symbolic links during archive extraction.

Vendors
langflow
Products
langflow
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news