PT-2026-91736 · Ibm · Langflow Oss
CVE-2026-12944
·
Published
2026-09-14
·
Updated
2026-10-04
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Langflow OSS versions 1.0.0 through 1.10.0
Description
An incomplete security scanner blocklist allows attackers to execute arbitrary Python code with root privileges (UID=0) on the server by submitting components that import
socket or urllib. This bypass results in the scanner incorrectly returning a validated: true signal. Successful exploitation enables Server-Side Request Forgery (SSRF) via IMDSv1 to steal AWS credentials with full IAM role permissions, arbitrary file exfiltration from the container filesystem, and lateral movement to internal services such as PostgreSQL and Redis within the Docker network.Recommendations
Update IBM Langflow OSS versions 1.0.0 through 1.10.0 to a newer version.
Fix
RCE
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Langflow Oss