IBM Langflow OSS 1.0.0
IBM Langflow OSS versions 1.0.0 through 1.11.5 can let an authenticated remote attacker execute arbitrary code. The attacker does this through special characters in a flow display name.
- Severity
- HighCVSS 3.1 · 8.8
- Fix
- Fixed in 1.11.6
- Affected versions
- 1.0.0 through 1.11.5
- Weakness
- CWE-94Code Injection
- Exploit likelihood
- 0.54% in 30 daysEPSS, higher than 44% of known flaws
- Affects
- Langflow OSS
- Exploited
- Not confirmedNo confirmation recorded
- CISA SSVC
- No known exploitationAutomatable: no · Technical impact: total
- EU ID
- EUVD-2026-75771ENISA vulnerability database
How it works
- An authenticated remote attacker can supply special characters in a flow display name.
- Langflow does not properly neutralize those characters.
- That can let the attacker execute arbitrary code.
What to do
Check the Langflow OSS version installed in the environment running Langflow. Versions 1.0.0 through 1.11.5 are within the affected range.
Upgrade Langflow OSS to version 1.11.6, following IBM's security bulletin.
Technical details
CVE-2026-81940 is a code-injection flaw involving special characters in flow display names. It requires network access and an authenticated account, with no additional user interaction. IBM rates it High with a CVSS score of 8.8.
Severity breakdown
- Attack vector Network Requires network access to the vulnerable service
- Attack complexity Low Low complexity under the assessed conditions
- Privileges required Low Attacker needs a basic user account
- User interaction None No victim action needed
- Scope Unchanged Impact stays within the same security authority
- Confidentiality impact High Sensitive data can be exposed with serious impact
- Integrity impact High Protected data can be changed with serious impact
- Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Open in FIRST.org calculatorReferences
- ibm.com · 7286666 vendor-advisory patch NVD
- cve.org · CVERecord vdb entry
- tenable.com · CVE-2026-81940 third party advisory vdb entry
- cvefeed.io · CVE-2026-81940 third party advisory vdb entry
- cveawg.mitre.org · CVE-2026-81940