ZeroHour

Vulnerabilities

119 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-81204
Unauthenticated Code Injection RCE in IBM Langflow OSS up to 1.11.5

IBM Langflow OSS versions 1.0.0 through 1.11.5 contain a code injection flaw (CWE-94) that occurs during graph construction, the process by which Langflow builds executable AI/agent workflow graphs. Because the CVSS 3.1 vector is network-exploitable with low complexity, no privileges, and no user interaction, a remote attacker who can reach the service can inject and execute arbitrary code on the underlying server without authenticating. Successful exploitation gives full control of the host — confidentiality, integrity, and availability are all rated high impact — and typically exposes any API keys, model credentials, or data configured in Langflow flows. All organizations running self-hosted IBM Langflow OSS in the affected range are at risk, especially instances exposed to the internet. As of now there is no known public proof of concept, no confirmed in-the-wild exploitation, and the flaw is not on the CISA KEV list, though the severity makes pre-patching attention warranted.

Do: Upgrade IBM Langflow OSS to a release newer than 1.11.5 as soon as a fixed version is available from IBM. If patching must wait, remove the instance from internet exposure (place behind a VPN or authenticated reverse proxy) since exploitation requires no credentials or user interaction. Review logs for unauthenticated requests to graph-construction/flow endpoints and for unexpected Python process or outbound network activity originating from the Langflow server.

9.8
group max
  • IBM Langflow OSS 1.0.0 through 1.11.5
moderate≈1,000–10,000 internet-exposed instances, plus a larger unknown number of internal/self-hosted deployments
CVE-2026-19298
Authenticated RCE via authorization bypass in IBM Langflow OSS 1.0.0–1.11.2

IBM Langflow OSS versions 1.0.0 through 1.11.2 contain an authorization bypass (code injection, CWE-94) in the flow build process, allowing attackers to execute arbitrary code. The flaw is triggered remotely by any attacker holding valid low-privilege credentials, who sends crafted requests to the flow build process where insufficient authorization checks permit injected code to run. Successful exploitation yields arbitrary code execution on the server with the service's privileges, with high impact to confidentiality, integrity, and availability (CVSS 3.1: 8.8). Any organization running Langflow OSS 1.0.0–1.11.2 is affected, particularly self-hosted instances exposed to the internet. There is no known exploitation in the wild, no public proof-of-concept, and a low predicted exploitation probability (EPSS 0.5%), and the issue is not in CISA's KEV catalog.

Do: Upgrade Langflow OSS from the affected 1.0.0–1.11.2 range to a fixed release newer than 1.11.2, checking IBM's and Langflow's advisories for the exact fixed version. Until upgraded, avoid exposing Langflow to the public internet, restrict which accounts hold credentials, and review access to the flow build endpoint. Defenders can confirm their deployed version and whether instances are internet-exposed.

8.8
group max
<1%
  • IBM Langflow OSS 1.0.0 through 1.11.2 (inclusive)
moderateon the order of 10,000–100,000 self-hosted instances/deployments worldwide
CVE-2026-19295
Authenticated OS command injection in IBM Langflow OSS

IBM Langflow OSS 1.0.0 through 1.11.1 contains a command/code injection flaw (CWE-95) in which a user-supplied 'type' field value in a saved flow is not neutralized when it is used during a flow build. An authenticated user can save a flow with a crafted type field value and then trigger a build of a wrapper flow that references it, causing the server process to execute attacker-controlled operating system commands. This escalates privileges from a restricted 'authenticated flow user' to arbitrary OS-level command execution running under the Langflow server process identity, and it works even when administrators have disabled custom components via LANGFLOW_ALLOW_CUSTOM_COMPONENTS=false. Any deployment running the affected versions is exposed, with the greatest risk where untrusted users can create or edit flows or where the server is network-reachable. Exploitation has not been observed: there is no public proof of concept, the flaw is not in CISA's KEV catalog, and EPSS currently gives it a 1% probability of exploitation in the next 30 days.

Do: Upgrade all Langflow OSS instances in the 1.0.0-1.11.1 range to the first patched release after 1.11.1, per IBM's advisory. Until patched, restrict who can save or create flows to trusted users and avoid exposing the server to the internet, and note that setting LANGFLOW_ALLOW_CUSTOM_COMPONENTS=false does not prevent this flaw. Audit saved flows for unexpected 'type' field values and review what privileges the Langflow service account holds on the host.

9.9
group max
<1%
  • IBM Langflow OSS 1.0.0 through 1.11.1 (inclusive)
largetens of thousands of deployments (roughly 1k-10k directly internet-exposed)
CVE-2026-19875
IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to overwrite administrator email information and abuse the server as an outbound relay due t

IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to overwrite administrator email information and abuse the server as an outbound relay due to missing authentication for the registration endpoint.

NVD description · AI analysis pending
7.5<1%
  • langflow langflow
CVE-2026-19297
IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to improper restriction of excessive authe

IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to improper restriction of excessive authentication attempts.

NVD description · AI analysis pending
9.1<1%
  • langflow langflow
CVE-2026-9205
+4 in the same advisory: …8478 …9196 …9201 …9130
IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function.

IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function.

NVD description · AI analysis pending
9.8
group max
<1%
  • langflow langflow