Remote Command Execution in IBM Langflow OSS Product
CVE-2026-17623
8.8HIGH
What is CVE-2026-17623?
IBM Langflow OSS versions 1.0.0 to 1.10.3 are susceptible to a remote command execution vulnerability. This results from improper validation of command inputs within MCP server configurations. An authenticated attacker could exploit this flaw to execute arbitrary commands on the server, posing significant security risks. It is crucial for users to review the vendor's advisory for available patches and mitigation steps to safeguard their systems.
Affected Version(s)
Langflow OSS 1.0.0 <= 1.10.3
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
CVEs reported to IBM: CVE-2026-8446 by odgrso (GMO CyberSecurity by Ierae, Inc.); CVE-2026-17626 by Thai Son Dinh (VinSOC Labs, (R&D).