IBM Langflow Vulnerability
Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.
CVSS Score
9.8
CRITICAL
Published
04 Aug 2026 00:00
Modified
N/A
Vendor
IBM
Product
Langflow
Source
CIRCL
Affected Versions
Fix
Vendor Patch / Mitigation Available
Weaknesses (CWE)
CWE-94
Affected Systems
IBM
Langflow
IBM
Langflow
External Links
KEV Status
Known Exploited Vulnerability