PT-2026-107253 · Ibm · Langflow Oss
CVE-2026-93447
·
Published
2026-10-06
·
Updated
2026-10-07
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IBM Langflow OSS versions 1.0.0 through 1.12.2
Description
An issue exists where an attacker with access to the server secret and Redis write access can submit a malicious serialized cache value. Upon retrieval, the deserialization process can execute attacker-controlled code with the privileges of the service process. Approximately 18.8k instances have been identified globally.
Recommendations
Update IBM Langflow OSS to a version later than 1.12.2.
Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Langflow Oss