ZeroHour

CVE-2026-81940

large

Authenticated Code Injection in IBM Langflow OSS via Flow Display Names

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

IBM Langflow OSS versions 1.0.0 through 1.11.5 fail to properly neutralize special characters in flow display names, a code-injection flaw (CWE-94) that leads to arbitrary code execution. A remote attacker who already holds valid low-privilege credentials can trigger it by defining or renaming a flow with crafted special characters in its display name, which the application subsequently evaluates as code; no user interaction is required. Successful exploitation gives the attacker arbitrary code execution in the context of the Langflow server process, with high impact on confidentiality, integrity, and availability (CVSS 3.1 8.8). Any Langflow OSS deployment running 1.0.0 through 1.11.5 and granting flow-editing rights to untrusted or semi-trusted users is affected, including self-hosted and containerized installations. No public proof of concept is known, the flaw is not in CISA KEV, and there are no confirmed reports of in-the-wild exploitation.

What to do: Upgrade Langflow OSS to the latest available release later than 1.11.5 as soon as a fixed version is published by IBM. Until then, restrict flow-creation and flow-renaming rights to trusted users, audit existing flow display names for unexpected special characters, and limit network exposure of Langflow instances. Monitor the IBM PSIRT advisory and watch for proof-of-concept code, since exploitation requires valid credentials, so also review for weak or shared accounts.

Affected
IBM Langflow OSS1.0.0 through 1.11.5
Estimated exposure
largeorder of 100,000+ users across tens of thousands of self-hosted instances (widely adopted OSS with 50k+ GitHub stars) — Langflow is one of the most-starred open-source LLM workflow tools and is typically self-hosted by development teams, implying tens of thousands of deployments, though the authenticated-privilege requirement limits how many are practically…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special characters in flow display names.

Vendors
langflow
Products
langflow
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.