CVE-2026-17632

IBM · Langflow OSS

IBM Langflow OSS is affected by a code injection vulnerability, allowing an authenticated attacker to execute arbitrary code within the application environment.

Executive summary

A critical code injection vulnerability in IBM Langflow OSS enables authenticated attackers to achieve full system compromise.

Vulnerability

This is an improper control of code generation (CWE-94) flaw. It allows an authenticated user to perform arbitrary code injection, which can lead to complete loss of confidentiality, integrity, and availability.

Business impact

With a CVSS score of 8.8, this vulnerability poses a severe threat to the entire application environment. Successful exploitation grants the attacker the ability to execute commands with the privileges of the application, potentially leading to full server takeover, data exfiltration, or the deployment of persistent malicious payloads.

Remediation

Immediate Action: Upgrade all instances of Langflow OSS to version 1.11.0 or newer as recommended by the vendor.

Proactive Monitoring: Monitor application logs for suspicious code execution patterns or unexpected process spawns that deviate from normal operational behavior.

Compensating Controls: Ensure the application runs with the least privilege necessary, and utilize container security policies to restrict the ability of the application process to execute shell commands or modify critical system files.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Due to the potential for total system compromise, this vulnerability requires immediate attention. All affected Langflow OSS deployments should be updated to the patched version 1.11.0 without delay to neutralize the risk of unauthorized code execution.