PT-2026-91736 · Ibm · Langflow Oss

CVE-2026-12944

·

Published

2026-09-14

·

Updated

2026-10-04

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions IBM Langflow OSS versions 1.0.0 through 1.10.0
Description An incomplete security scanner blocklist allows attackers to execute arbitrary Python code with root privileges (UID=0) on the server by submitting components that import socket or urllib. This bypass results in the scanner incorrectly returning a validated: true signal. Successful exploitation enables Server-Side Request Forgery (SSRF) via IMDSv1 to steal AWS credentials with full IAM role permissions, arbitrary file exfiltration from the container filesystem, and lateral movement to internal services such as PostgreSQL and Redis within the Docker network.
Recommendations Update IBM Langflow OSS versions 1.0.0 through 1.10.0 to a newer version.

Fix

RCE

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12944

Affected Products

Langflow Oss