PT-2026-60866 · Ibm · Langflow Oss

·

CVE-2026-8505

·

Published

2026-07-17

·

Updated

2026-07-23

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM Langflow OSS versions 1.0.0 through 1.10.0
Description A flaw in the webhook authentication logic allows unauthenticated users to trigger the execution of any flow. The system incorrectly bypasses API key validation when the WEBHOOK AUTH ENABLE configuration is set to False, which is the default setting. A remote attacker who knows a flow's UUID can execute it as the owner, potentially leading to Remote Code Execution (RCE), a state where an attacker can execute arbitrary commands on the host machine.
Recommendations Update IBM Langflow OSS to version 1.10.1. Enable webhook authentication by setting WEBHOOK AUTH ENABLE to True. Avoid exposing builder APIs.

Fix

RCE

DoS

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-8505

Affected Products

Langflow Oss