ZeroHour

CVE-2026-81211

moderate

Authenticated Python Code Execution in IBM Langflow OSS via Missing Authorization

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

IBM Langflow OSS versions 1.0.0 through 1.11.5 contain an improper authorization flaw (CWE-862) affecting custom components used in stored flows, meaning the application fails to adequately verify permissions when these components run. A remote attacker who holds valid low-privileged credentials can trigger execution of a stored flow's custom components over the network and have arbitrary Python code executed on the server. Successful exploitation grants code execution with the application's privileges, with high impact to confidentiality, integrity, and availability, and can lead to full server compromise given Langflow's flexible component model. Any deployment of Langflow OSS in the affected version range is exposed, with risk concentrated in shared or multi-tenant instances where untrusted or low-privilege users can run flows. The vulnerability is not listed in CISA's KEV catalog and no public proof-of-concept or known in-the-wild exploitation has been reported.

What to do: Upgrade Langflow OSS to a fixed release beyond 1.11.5 as soon as IBM publishes a patched version, and check the IBM PSIRT advisory for the recommended version. Until patched, restrict flow execution and flow-editing permissions to trusted users only, avoid exposing Langflow directly to the internet, and review logs for unexpected Python execution or unusual flow runs by low-privilege accounts.

Affected
IBM Langflow OSS1.0.0 through 1.11.5
Estimated exposure
moderateroughly 1,000-10,000 internet-exposed instances, with additional internal deployments — Public internet scans during 2025 exploitation of an earlier Langflow RCE found only a few thousand Langflow servers exposed online, and total deployments are likely higher but still short of mass scale because Langflow is primarily a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary Python code due to improper authorization of custom components in stored flows.

Vendors
langflow
Products
langflow
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.