Cryptographic Weakness in IBM Langflow OSS Leading to Arbitrary Code Execution
CVE-2026-9201
8.8HIGH
What is CVE-2026-9201?
A vulnerability in IBM Langflow OSS versions 1.0.0 through 1.10.3 allows an authenticated attacker to exploit a cryptographic weakness in the custom component validation. The application uses a truncated SHA-256 hash for validating component code, relying on a limited portion of the digest. By crafting malicious component code that can collide with a trusted template hash, an attacker can bypass security measures. This exploitation enables the execution of unauthorized Python code within the Langflow process, potentially leading to full system compromise.
Affected Version(s)
Langflow OSS 1.0.0 <= 1.10.3