IBM has disclosed 25 vulnerabilities in Langflow OSS, affecting versions 1.0.0 through 1.12.2. Two of these are critical flaws that allow unauthenticated remote code execution. The security bulletin recommends upgrading to version 1.12.3, and it does not list any workarounds.
Langflow provides a visual environment for building AI agents and workflows, featuring customization with Python components and built-in API and MCP servers. These capabilities position its code execution and data access safeguards at critical security boundaries.
The highest-rated vulnerabilities, CVE-2026-104334 and CVE-2026-93674, each have an IBM-assigned CVSS score of 9.8. The vulnerability vectors indicate they can be exploited remotely, with low attack complexity, no required privileges, and no user interaction necessary. This poses significant risks to confidentiality, integrity, and availability.
Most of the remaining execution vulnerabilities require the attacker to be authenticated. These include sandbox escape, inadequate input validation, code-generation controls, command-handling problems, and an incomplete security-scanner blocklist.
CVE-2026-93675 is an exception: it involves a dependency confusion scenario that requires user interaction but does not require attacker privileges, according to its vulnerability vector.
CVE-2026-97677 allows an authenticated flow author to write attacker-controlled content into directories writable by the service account, bypassing local file isolation. A specially crafted index on disk can also expose accessible configuration files, secrets, or application databases.
CVE-2026-97680 affects vertex result caching and could disclose sensitive information or allow injection of malicious data due to improper access controls.
Another cache-related issue, CVE-2026-93447, requires access to the server secret and Redis write permissions. Retrieving a malicious serialized cache value could execute attacker-controlled code with the service process’s privileges.
IBM has identified version 1.12.3 as the remediation release. IBM published this version on September 22, 2026, and followed it with version 1.12.4, released on September 29, 2026.
The bulletin provides no evidence of active exploitation, publicly available exploits, or confirmed compromises. The actual exposure depends on the deployment configuration and attacker access, and it is important to distinguish authenticated vulnerabilities from the two unauthenticated critical execution flaws.
CVE Details
| CVE | CVSS | CWE | Vulnerability |
|---|---|---|---|
| CVE-2026-104334 | 9.8 | 94 | Unauthenticated code injection |
| CVE-2026-97677 | 8.1 | 22 | Arbitrary file access |
| CVE-2026-97676 | 8.8 | 94 | Sandbox escape |
| CVE-2026-101329 | 6.5 | 284 | Sensitive-information disclosure |
| CVE-2026-97680 | 8.3 | 284 | Cache access-control failure |
| CVE-2026-97678 | 8.8 | 693 | Input-validation execution |
| CVE-2026-97673 | 8.8 | 693 | Input-validation execution |
| CVE-2026-97655 | 8.8 | 94 | Scanner blocklist bypass |
| CVE-2026-97679 | 8.8 | 94 | Code injection |
| CVE-2026-101331 | 7.7 | 522 | Insufficiently protected credentials |
| CVE-2026-97674 | 8.1 | 94 | OS command execution |
| CVE-2026-103360 | 8.1 | 22 | Path traversal |
| CVE-2026-88962 | 8.8 | 94 | Code-generation injection |
| CVE-2026-93674 | 9.8 | 94 | Unauthenticated command injection |
| CVE-2026-93679 | 4.3 | 400 | ZIP resource exhaustion |
| CVE-2026-93443 | 7.5 | 94 | Code injection |
| CVE-2026-93678 | 7.6 | 639 | Authorization bypass |
| CVE-2026-93677 | 7.7 | 200 | Sensitive-information exposure |
| CVE-2026-93445 | 8.1 | 94 | Code-generation injection |
| CVE-2026-93447 | 7.5 | 502 | Untrusted cache deserialization |
| CVE-2026-93449 | 8.5 | 94 | Code-generation injection |
| CVE-2026-93675 | 8.8 | 440 | Dependency confusion |
| CVE-2026-93448 | 6.5 | 22 | Path traversal |
| CVE-2026-97671 | 6.5 | 22 | Path traversal |
| CVE-2026-104335 | 8.8 | 284 | Access-control execution flaw |
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…
A threat actor published a malicious version of the tensorlake npm package on October 8,…
A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…
A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…
16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…
Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…