Remote Code Injection Vulnerability in IBM Langflow OSS
CVE-2026-8478
8.8HIGH
What is CVE-2026-8478?
IBM Langflow OSS versions 1.0.0 to 1.10.3 have a vulnerability that could allow attackers to remotely execute arbitrary code on the system. This issue arises from improper validation of user input, which could be exploited to introduce unauthorized code, compromising the security and integrity of the application. Users are advised to apply patches provided by IBM to mitigate this risk.
Affected Version(s)
Langflow OSS 1.0.0 <= 1.10.3