Arbitrary Code Execution Vulnerability in IBM Langflow OSS
CVE-2026-93449

8.5HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
7 October 2026

What is CVE-2026-93449?

A vulnerability in IBM Langflow OSS versions 1.0.0 through 1.12.2 allows remote authenticated attackers to execute arbitrary code. This is primarily due to inadequate control over code generation, which could lead to serious security implications if exploited. It is crucial for users to ensure their systems are updated and protected against this threat, as it can facilitate unauthorized access and manipulation of systems.

Affected Version(s)

Langflow OSS 1.0.0 <= 1.12.2

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.