Remote Code Execution Vulnerability in IBM Langflow OSS Software
CVE-2026-93675

8.8HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
7 October 2026

What is CVE-2026-93675?

IBM Langflow OSS versions 1.0.0 to 1.12.2 are susceptible to a security vulnerability that may allow a remote attacker to execute arbitrary code on the affected systems. This vulnerability arises from unexpected dependency confusion, which can lead to unauthorized code execution. It is crucial for users and administrators of the affected versions to apply the necessary patches available from IBM to mitigate the risks associated with this vulnerability.

Affected Version(s)

Langflow OSS 1.0.0 <= 1.12.2

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.