ZeroHour

CVE-2026-78569

moderate

OS Command Injection in IBM Langflow OSS Enables Authenticated RCE

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

IBM Langflow OSS versions 1.0.0 through 1.11.5 contain an OS command injection flaw (CWE-78) in the product's built-in security scanner, where an incomplete denylist of characters or patterns fails to block crafted input. An authenticated attacker with low privileges can send a crafted request over the network, with no user interaction required, and the insufficiently filtered input is passed to the operating system, resulting in execution of arbitrary code. Successful exploitation yields high impact across confidentiality, integrity, and availability (CVSS 3.1 of 8.8), effectively allowing full compromise of the host or container running the Langflow service. All deployments running Langflow OSS 1.0.0 through 1.11.5 are affected, with risk concentrated in self-hosted instances used for AI/LLM application development. As of publication there is no public proof-of-concept, the issue is not in CISA KEV, and no in-the-wild exploitation has been reported.

What to do: Upgrade all Langflow OSS deployments beyond version 1.11.5 to the latest patched release as identified in IBM's advisory (a specific fixed version was not provided in this data, so confirm the fixed release with IBM/[email protected] before deploying). In the interim, restrict authentication to trusted users only and limit what the Langflow process can execute on the host, since exploitation requires valid credentials. Check your deployed version via the admin UI or container tag, and monitor IBM's advisory for confirmation of the fix.

Affected
IBM Langflow OSS1.0.0 through 1.11.5 (inclusive)
Estimated exposure
moderatelikely in the low thousands of internet-exposed instances, with total installs plausibly in the tens of thousands — Langflow is a popular open-source LLM workflow builder typically self-hosted by development teams; public internet scans of Langflow instances have historically counted in the low thousands, supporting a moderate-scale estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to execute arbitrary code due to an incomplete denylist in the security scanner.

Vendors
langflow
Products
langflow
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.