PT-2026-107253 · Ibm · Langflow Oss

CVE-2026-93447

·

Published

2026-10-06

·

Updated

2026-10-07

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM Langflow OSS versions 1.0.0 through 1.12.2
Description An issue exists where an attacker with access to the server secret and Redis write access can submit a malicious serialized cache value. Upon retrieval, the deserialization process can execute attacker-controlled code with the privileges of the service process. Approximately 18.8k instances have been identified globally.
Recommendations Update IBM Langflow OSS to a version later than 1.12.2.

Fix

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93447

Affected Products

Langflow Oss