CVE-2026-17633

IBM · Langflow OSS

IBM Langflow OSS is vulnerable to improper control of code generation, which may allow an authenticated attacker to perform code injection attacks.

Executive summary

A critical code injection vulnerability in IBM Langflow OSS versions 1.0.0 through 1.10.3 allows authenticated attackers to execute arbitrary code with elevated privileges.

Vulnerability

This vulnerability involves improper control of code generation, classified as CWE-94. It requires a low-privileged authenticated attacker to successfully exploit the flaw.

Business impact

The ability to perform code injection poses a severe risk to the integrity and confidentiality of the affected system. A successful exploit could lead to full system compromise, unauthorized data access, or the execution of malicious commands, which justifies the high CVSS score of 8.5.

Remediation

Immediate Action: Upgrade to Langflow OSS version 1.11.0 or newer as recommended by the vendor.

Proactive Monitoring: Review application logs for suspicious code execution patterns or unauthorized requests originating from authenticated user accounts.

Compensating Controls: Implement strict input validation and access controls to limit the capabilities of authenticated users, and ensure the application runs with the minimum necessary privileges.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for total impact on system security, administrators must prioritize upgrading to version 1.11.0. Failure to patch allows persistent risk to the application environment, making immediate remediation essential for maintaining a secure posture.