IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary code

Published September 10, 2026 CVE-2026-81204

IBM Langflow OSS has a flaw that can let a remote attacker run their own code through Langflow. The issue affects versions 1.0.0 through 1.11.5.

Severity
CriticalCVSS 3.1 · 9.8
Fix
Fixed in 1.11.6
Affected versions
1.0.0 through 1.11.5
Weakness
CWE-94Code Injection
Exploit likelihood
0.60% in 30 daysEPSS, higher than 47% of known flaws
Affects
Langflow OSS
Exploited
Not confirmedNo confirmation recorded
CISA SSVC
No known exploitationAutomatable: yes · Technical impact: total
EU ID
EUVD-2026-75784ENISA vulnerability database

What to do

Check the installed Langflow OSS version against the affected range, 1.0.0 through 1.11.5.

If the installed version is in that range, upgrade Langflow OSS to version 1.11.6. See IBM's security bulletin for the advisory details.

Technical details

CVE-2026-81204 is a network-reachable code-injection flaw with no authentication or user interaction required. IBM's CVE record rates its confidentiality, integrity, and availability impact as high.

Severity breakdown

  • Attack vector Network Requires network access to the vulnerable service
  • Attack complexity Low Low complexity under the assessed conditions
  • Privileges required None Attacker needs no account or login
  • User interaction None No victim action needed
  • Scope Unchanged Impact stays within the same security authority
  • Confidentiality impact High Sensitive data can be exposed with serious impact
  • Integrity impact High Protected data can be changed with serious impact
  • Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Open in FIRST.org calculator

References