IBM Langflow OSS 1.0.0
An attacker with a Langflow account could run their own code on the Langflow server. That may let them access, change, or disrupt server activity.
- Severity
- HighCVSS 3.1 · 8.8
- Fix
- Fixed in 1.11.6
- Affected versions
- 1.0.0 through 1.11.5
- Weakness
- CWE-78OS Command Injection
- Exploit likelihood
- 0.45% in 30 daysEPSS, higher than 38% of known flaws
- Affects
- Langflow OSS
- Exploited
- Not confirmedNo confirmation recorded
- EU ID
- EUVD-2026-75800ENISA vulnerability database
How it works
- The supplied sources do not explain what input the attacker sends or how Langflow processes it.
- Not enough public detail to say.
What to do
Check the installed Langflow OSS version and compare it with IBM's advisory. Versions from 1.0.0 through 1.11.5 are listed as affected.
Upgrade Langflow OSS to version 1.11.6, as IBM recommends in its security bulletin.
Technical details
Affected software: Langflow OSSby IBM
CVE-2026-78569 is an authenticated remote code-execution flaw in Langflow OSS. IBM rates it high, with a CVSS score of 8.8.
Severity breakdown
- Attack vector Network Requires network access to the vulnerable service
- Attack complexity Low Low complexity under the assessed conditions
- Privileges required Low Attacker needs a basic user account
- User interaction None No victim action needed
- Scope Unchanged Impact stays within the same security authority
- Confidentiality impact High Sensitive data can be exposed with serious impact
- Integrity impact High Protected data can be changed with serious impact
- Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Open in FIRST.org calculatorReferences
- ibm.com · 7286666 vendor-advisory patch NVD
- cve.org · CVERecord vdb entry
- tenable.com · CVE-2026-78569 third party advisory vdb entry
- cvefeed.io · CVE-2026-78569 third party advisory vdb entry
- cveawg.mitre.org · CVE-2026-78569