PT-2026-89625 · Ibm · Langflow Oss
CVE-2026-81204
·
Published
2026-09-10
·
Updated
2026-09-11
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
🚨Critical - IBM Langflow OSS Graph Construction Code Injection (CVE-2026-81204)
IBM Langflow OSS graph construction accepts attacker-controlled node/graph definitions that can inject code during graph build due to missing execution guards and incomplete security controls. Remote exploitation enables arbitrary code execution on the Langflow host. Deployments that do not accept untrusted graphs are not impacted.
👉Affected: langflow 1.0.0-1.11.5
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Langflow Oss