Remote Code Execution Vulnerability in IBM Langflow OSS
CVE-2026-81211
8.8HIGH
What is CVE-2026-81211?
IBM Langflow OSS versions 1.0.0 through 1.11.5 are susceptible to a remote code execution vulnerability that arises from the improper authorization of custom components within stored flows. This flaw enables an authenticated attacker to leverage the system to execute arbitrary Python code, potentially leading to unauthorized access and compromise of sensitive data. It is crucial for users to apply the necessary patches provided by IBM to mitigate this security risk.
Affected Version(s)
Langflow OSS 1.0.0 <= 1.11.5