Command Execution Vulnerability in IBM Langflow OSS
CVE-2026-78575
8.8HIGH
What is CVE-2026-78575?
IBM Langflow OSS versions 1.0.0 to 1.11.5 contain a vulnerability that could allow a remote authenticated attacker to execute arbitrary commands. This security flaw arises from insufficient validation of command-line arguments within the MCP stdio server configuration. If exploited, the vulnerability may lead to unauthorized access and potential manipulation of the system.
Affected Version(s)
Langflow OSS 1.0.0 <= 1.11.5