ZeroHour

CVE-2026-79742

moderate

Authenticated RCE in IBM Langflow OSS via incomplete environment variable blocklist

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

IBM Langflow OSS 1.0.0 through 1.11.5 contains a code injection flaw (CWE-94) caused by an incomplete blocklist of environment variables that authenticated users can set or reference from flows. A remote attacker with valid low-privilege credentials can send a crafted request that reaches code-evaluation functionality through an environment variable not covered by the blocklist, causing attacker-controlled code to execute. Successful exploitation yields arbitrary code execution with the privileges of the Langflow service, enabling compromise of the host, flows, and connected data sources. All deployments of Langflow OSS in the affected version range are exposed, with practical risk concentrated on network-reachable instances where an attacker can obtain or already holds an account. There is currently no evidence of exploitation: the flaw is not in CISA's KEV and no public proof-of-concept is known.

What to do: Upgrade IBM Langflow OSS to a fixed release later than 1.11.5, checking IBM's PSIRT advisory for the specific fixed version since it is not stated in the available data. Until patched, restrict Langflow access to trusted authenticated users, limit the environment variables available to flows, and avoid exposing the Langflow UI/API to the internet. Review logs for unexpected environment variable changes or anomalous process executions initiated by the Langflow service.

Affected
IBM Langflow OSS1.0.0 through 1.11.5
Estimated exposure
moderate≈10,000–50,000 internet-exposed/self-hosted Langflow instances (best estimate; authentication required limits practical attack surface) — Langflow has seen broad self-hosted adoption in the AI-builder community, and public internet scans during the 2025 Langflow RCE wave observed tens of thousands of exposed instances, though this flaw additionally requires a valid…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an incomplete environment variable blocklist.

Vendors
langflow
Products
langflow
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.