CVE-2026-79742
8.8IBM · Langflow OSS
IBM Langflow OSS versions 1.0.0 through 1.11.5 contain a code injection vulnerability caused by an incomplete environment variable blocklist, allowing remote authenticated code execution.
Executive summary
A critical remote code execution vulnerability in IBM Langflow OSS allows authenticated attackers to compromise system integrity and availability.
Vulnerability
This vulnerability is a code injection flaw (CWE-94) resulting from an insufficient blocklist for environment variables. A remote attacker with authenticated access can leverage this weakness to execute arbitrary code on the underlying host system.
Business impact
The ability for an authenticated user to execute arbitrary code poses a severe risk to the confidentiality, integrity, and availability of the affected environment. With a CVSS score of 8.8, this high-severity vulnerability could lead to total system compromise, unauthorized data access, or the deployment of further malicious payloads, necessitating immediate remediation to prevent potential lateral movement within the network.
Remediation
Immediate Action: Upgrade IBM Langflow OSS to version 1.11.6 or later as recommended by the vendor.
Proactive Monitoring: Review application and system access logs for anomalous execution patterns or unauthorized modification of environment variables.
Compensating Controls: Implement network segmentation and restrict access to the Langflow interface to only trusted users to minimize the attack surface until the patch is applied.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high CVSS score and the potential for remote code execution, this vulnerability represents a significant security risk. Administrators should prioritize upgrading to version 1.11.6 immediately to eliminate the underlying code injection vector. Failure to patch allows any authenticated user to potentially gain control over the host server, which is an unacceptable risk for most enterprise production environments.
More IBM CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section