IBM Langflow OSS 1.0.0

Published September 10, 2026 CVE-2026-78569

An attacker with a Langflow account could run their own code on the Langflow server. That may let them access, change, or disrupt server activity.

Severity
HighCVSS 3.1 · 8.8
Fix
Fixed in 1.11.6
Affected versions
1.0.0 through 1.11.5
Weakness
CWE-78OS Command Injection
Exploit likelihood
0.45% in 30 daysEPSS, higher than 38% of known flaws
Affects
Langflow OSS
Exploited
Not confirmedNo confirmation recorded
EU ID
EUVD-2026-75800ENISA vulnerability database

How it works

  • The supplied sources do not explain what input the attacker sends or how Langflow processes it.
  • Not enough public detail to say.

What to do

Check the installed Langflow OSS version and compare it with IBM's advisory. Versions from 1.0.0 through 1.11.5 are listed as affected.

Upgrade Langflow OSS to version 1.11.6, as IBM recommends in its security bulletin.

Technical details

Affected software: Langflow OSSby IBM

CVE-2026-78569 is an authenticated remote code-execution flaw in Langflow OSS. IBM rates it high, with a CVSS score of 8.8.

Severity breakdown

  • Attack vector Network Requires network access to the vulnerable service
  • Attack complexity Low Low complexity under the assessed conditions
  • Privileges required Low Attacker needs a basic user account
  • User interaction None No victim action needed
  • Scope Unchanged Impact stays within the same security authority
  • Confidentiality impact High Sensitive data can be exposed with serious impact
  • Integrity impact High Protected data can be changed with serious impact
  • Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Open in FIRST.org calculator

References