CVE-2026-78575

8.8

IBM · Langflow OSS

IBM Langflow OSS versions 1.0.0 through 1.11.5 are vulnerable to OS command injection via improper validation of command-line arguments in the MCP stdio server configuration.

Executive summary

An authenticated remote attacker can execute arbitrary OS commands in IBM Langflow OSS, posing a high risk of complete system compromise.

Vulnerability

The application fails to properly neutralize special elements within the MCP stdio server configuration, leading to OS command injection (CWE-78). This vulnerability requires the attacker to have authenticated access to the system.

Business impact

Successful exploitation of this flaw allows an authenticated user to execute arbitrary commands on the underlying host, potentially leading to full system takeover. Given the CVSS score of 8.8, this vulnerability presents a significant risk to data confidentiality, integrity, and availability. Unauthorized command execution could enable attackers to exfiltrate sensitive data, pivot to internal networks, or disrupt critical business operations.

Remediation

Immediate Action: Upgrade IBM Langflow OSS to version 1.11.6 as recommended by the vendor.

Proactive Monitoring: Review system and application logs for suspicious process execution patterns or unusual command-line arguments originating from the Langflow service account.

Compensating Controls: Restrict access to the Langflow interface to authorized personnel only and implement strict network segmentation to limit the potential impact of a compromised instance.

Exploitation status

Public Exploit Available: No — exploit_available is unknown.

Analyst recommendation

The vulnerability in IBM Langflow OSS represents a high-severity risk due to the potential for arbitrary code execution. Organizations should prioritize updating to version 1.11.6 immediately to eliminate the underlying command injection vector. Failure to remediate could allow an authenticated adversary to gain unauthorized control over the affected server environment.

More IBM CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources