Cryptographic Weakness in IBM Langflow OSS Leading to Arbitrary Code Execution
CVE-2026-9201

8.8HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
5 August 2026

What is CVE-2026-9201?

A vulnerability in IBM Langflow OSS versions 1.0.0 through 1.10.3 allows an authenticated attacker to exploit a cryptographic weakness in the custom component validation. The application uses a truncated SHA-256 hash for validating component code, relying on a limited portion of the digest. By crafting malicious component code that can collide with a trusted template hash, an attacker can bypass security measures. This exploitation enables the execution of unauthorized Python code within the Langflow process, potentially leading to full system compromise.

Affected Version(s)

Langflow OSS 1.0.0 <= 1.10.3

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.