Remote Code Execution Vulnerability in IBM Langflow OSS
CVE-2026-97676
8.8HIGH
What is CVE-2026-97676?
IBM Langflow OSS versions 1.0.0 through 1.12.2 are susceptible to a remote code execution vulnerability caused by improper handling of special elements within code execution contexts. This flaw may enable an authenticated remote attacker to execute arbitrary code, leading to a potential sandbox escape, thereby compromising system security. It is crucial for users to apply available patches to mitigate associated risks.
Affected Version(s)
Langflow OSS 1.0.0 <= 1.12.2