ESC
Type to search CVEs in real-time
Enter open Esc close Ctrl K toggle

CVE-2026-9198

CRITICAL Export PDF

IBM Langflow Vulnerability

Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.

CVSS Score
9.8
CRITICAL
Published
04 Aug 2026 00:00
Modified
N/A
Vendor
IBM
Product
Langflow
Source
CIRCL

Affected Versions

Fix Vendor Patch / Mitigation Available

Weaknesses (CWE)

CWE-94

Affected Systems

IBM
Langflow
IBM
Langflow

KEV Status

Known Exploited Vulnerability