IBM patched 25 Langflow OSS flaws, including two unauthenticated critical remote code execution bugs, in version 1.12.3.
IBM disclosed 25 vulnerabilities in Langflow OSS affecting versions 1.0.0 through 1.12.2 and recommends upgrading to 1.12.3, with no workarounds. CVE-2026-104334 and CVE-2026-93674 are unauthenticated remote code execution flaws, each scored CVSS 9.8. Most other execution bugs require authentication and include sandbox escape, path traversal, unsafe caching, and dependency confusion. IBM reported no active exploitation, public exploits, or confirmed compromises; version 1.12.4 followed on September 29, 2026.
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-93674 | Unauthenticated RCE in IBM Langflow OSS 1.0.0–1.12.2 CVE-2026-93674 is a critical unauthenticated remote code execution flaw in IBM Langflow OSS caused by improper neutralization of special elements used in an OS command (CWE-94). A remote attacker can trigger it over the network with no privileges and no user interaction and run arbitrary code on the host. Successful exploitation fully compromises confidentiality, integrity, and availability of the affected instance (CVSS 3.1 base score 9.8). Langflow OSS versions 1.0.0 through 1.12.2 are affected. A public proof-of-concept exists, but the issue is not in CISA’s Known Exploited Vulnerabilities catalog and in-the-wild exploitation is not confirmed in the provided data. Do: Upgrade IBM Langflow OSS to a release newer than 1.12.2 as directed in IBM’s security update, and do not leave instances reachable from the internet. Until patched, restrict access to trusted networks and review logs for unexpected command or code execution. Treat any unpatched 1.0.0–1.12.2 deployment as critically exposed because the flaw is remotely exploitable without authentication. |
IBM has disclosed 25 vulnerabilities in Langflow OSS, affecting versions 1.0.0 through 1.12.2. Two of these are critical flaws that allow unauthenticated remote code execution. The security bulletin recommends upgrading to version 1.12.3, and it does not list any workarounds.
Langflow provides a visual environment for building AI agents and workflows, featuring customization with Python components and built-in API and MCP servers. These capabilities position its code execution and data access safeguards at critical security boundaries.
The highest-rated vulnerabilities, CVE-2026-104334 and CVE-2026-93674, each have an IBM-assigned CVSS score of 9.8. The vulnerability vectors indicate they can be exploited remotely, with low attack complexity, no required privileges, and no user interaction necessary. This poses significant risks to confidentiality, integrity, and availability.
Most of the remaining execution vulnerabilities require the attacker to be authenticated. These include sandbox escape, inadequate input validation, code-generation controls, command-handling problems, and an incomplete security-scanner blocklist.
CVE-2026-93675 is an exception: it involves a dependency confusion scenario that requires user interaction but does not require attacker privileges, according to its vulnerability vector.
CVE-2026-97677 allows an authenticated flow author to write attacker-controlled content into directories writable by the service account, bypassing local file isolation. A specially crafted index on disk can also expose accessible configuration files, secrets, or application databases.
CVE-2026-97680 affects vertex result caching and could disclose sensitive information or allow injection of malicious data due to improper access controls.
Another cache-related issue, CVE-2026-93447, requires access to the server secret and Redis write permissions. Retrieving a malicious serialized cache value could execute attacker-controlled code with the service process’s privileges.
IBM has identified version 1.12.3 as the remediation release. IBM published this version on September 22, 2026, and followed it with version 1.12.4, released on September 29, 2026.
The bulletin provides no evidence of active exploitation, publicly available exploits, or confirmed compromises. The actual exposure depends on the deployment configuration and attacker access, and it is important to distinguish authenticated vulnerabilities from the two unauthenticated critical execution flaws.
CVE Details
| CVE | CVSS | CWE | Vulnerability |
|---|---|---|---|
| CVE-2026-104334 | 9.8 | 94 | Unauthenticated code injection |
| CVE-2026-97677 | 8.1 | 22 | Arbitrary file access |
| CVE-2026-97676 | 8.8 | 94 | Sandbox escape |
| CVE-2026-101329 | 6.5 | 284 | Sensitive-information disclosure |
| CVE-2026-97680 | 8.3 | 284 | Cache access-control failure |
| CVE-2026-97678 | 8.8 | 693 | Input-validation execution |
| CVE-2026-97673 | 8.8 | 693 | Input-validation execution |
| CVE-2026-97655 | 8.8 | 94 | Scanner blocklist bypass |
| CVE-2026-97679 | 8.8 | 94 | Code injection |
| CVE-2026-101331 | 7.7 | 522 | Insufficiently protected credentials |
| CVE-2026-97674 | 8.1 | 94 | OS command execution |
| CVE-2026-103360 | 8.1 | 22 | Path traversal |
| CVE-2026-88962 | 8.8 | 94 | Code-generation injection |
| CVE-2026-93674 | 9.8 | 94 | Unauthenticated command injection |
| CVE-2026-93679 | 4.3 | 400 | ZIP resource exhaustion |
| CVE-2026-93443 | 7.5 | 94 | Code injection |
| CVE-2026-93678 | 7.6 | 639 | Authorization bypass |
| CVE-2026-93677 | 7.7 | 200 | Sensitive-information exposure |
| CVE-2026-93445 | 8.1 | 94 | Code-generation injection |
| CVE-2026-93447 | 7.5 | 502 | Untrusted cache deserialization |
| CVE-2026-93449 | 8.5 | 94 | Code-generation injection |
| CVE-2026-93675 | 8.8 | 440 | Dependency confusion |
| CVE-2026-93448 | 6.5 | 22 | Path traversal |
| CVE-2026-97671 | 6.5 | 22 | Path traversal |
| CVE-2026-104335 | 8.8 | 284 | Access-control execution flaw |
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.
Text extracted automatically; images, tables and formatting may be missing. Original: https://gbhackers.com/ibm-patches-multiple-langflow-oss-flaws/
| 9.8 group max |
| <1% |
| PoC |
|
| — |
| CVE-2026-104335 | Authenticated RCE via access control flaw in IBM Langflow OSS IBM Langflow OSS 1.0.0 through 1.12.2 has an improper access control flaw (CWE-284) that allows a remote authenticated attacker to execute arbitrary code. The attack is network-reachable, low complexity, needs only low privileges, and does not require user interaction. A successful attack has high impact on confidentiality, integrity, and availability of the Langflow instance (CVSS 3.1 base score 8.8). Anyone running those Langflow OSS versions is affected. No public proof of concept is known, and the issue is not in CISA's Known Exploited Vulnerabilities catalog. Do: Upgrade IBM Langflow OSS to a vendor-patched release newer than 1.12.2 as soon as IBM publishes it; the advisory range ends at 1.12.2 and no fixed version is stated in the provided data. Until then, keep instances off the public internet, limit accounts to trusted users (any low-privilege login is enough), and watch for unexpected code or workflow execution. | 8.8 | — |
| — |
| CVE-2026-97677 | NVD description · AI analysis pending | — | — | — | — | — |