Cyber Security News

IBM Patches Multiple Langflow OSS Flaws Including Two Critical RCE Vulnerabilities

IBM has disclosed 25 vulnerabilities in Langflow OSS, affecting versions 1.0.0 through 1.12.2. Two of these are critical flaws that allow unauthenticated remote code execution. The security bulletin recommends upgrading to version 1.12.3, and it does not list any workarounds.

Langflow provides a visual environment for building AI agents and workflows, featuring customization with Python components and built-in API and MCP servers. These capabilities position its code execution and data access safeguards at critical security boundaries.

IBM Patches Multiple Langflow OSS Flaws

The highest-rated vulnerabilities, CVE-2026-104334 and CVE-2026-93674, each have an IBM-assigned CVSS score of 9.8. The vulnerability vectors indicate they can be exploited remotely, with low attack complexity, no required privileges, and no user interaction necessary. This poses significant risks to confidentiality, integrity, and availability.

Most of the remaining execution vulnerabilities require the attacker to be authenticated. These include sandbox escape, inadequate input validation, code-generation controls, command-handling problems, and an incomplete security-scanner blocklist.

CVE-2026-93675 is an exception: it involves a dependency confusion scenario that requires user interaction but does not require attacker privileges, according to its vulnerability vector.

CVE-2026-97677 allows an authenticated flow author to write attacker-controlled content into directories writable by the service account, bypassing local file isolation. A specially crafted index on disk can also expose accessible configuration files, secrets, or application databases.

CVE-2026-97680 affects vertex result caching and could disclose sensitive information or allow injection of malicious data due to improper access controls.

Another cache-related issue, CVE-2026-93447, requires access to the server secret and Redis write permissions. Retrieving a malicious serialized cache value could execute attacker-controlled code with the service process’s privileges.

IBM has identified version 1.12.3 as the remediation release. IBM published this version on September 22, 2026, and followed it with version 1.12.4, released on September 29, 2026.

The bulletin provides no evidence of active exploitation, publicly available exploits, or confirmed compromises. The actual exposure depends on the deployment configuration and attacker access, and it is important to distinguish authenticated vulnerabilities from the two unauthenticated critical execution flaws.

CVE Details

CVECVSSCWEVulnerability
CVE-2026-1043349.894Unauthenticated code injection
CVE-2026-976778.122Arbitrary file access
CVE-2026-976768.894Sandbox escape
CVE-2026-1013296.5284Sensitive-information disclosure
CVE-2026-976808.3284Cache access-control failure
CVE-2026-976788.8693Input-validation execution
CVE-2026-976738.8693Input-validation execution
CVE-2026-976558.894Scanner blocklist bypass
CVE-2026-976798.894Code injection
CVE-2026-1013317.7522Insufficiently protected credentials
CVE-2026-976748.194OS command execution
CVE-2026-1033608.122Path traversal
CVE-2026-889628.894Code-generation injection
CVE-2026-936749.894Unauthenticated command injection
CVE-2026-936794.3400ZIP resource exhaustion
CVE-2026-934437.594Code injection
CVE-2026-936787.6639Authorization bypass
CVE-2026-936777.7200Sensitive-information exposure
CVE-2026-934458.194Code-generation injection
CVE-2026-934477.5502Untrusted cache deserialization
CVE-2026-934498.594Code-generation injection
CVE-2026-936758.8440Dependency confusion
CVE-2026-934486.522Path traversal
CVE-2026-976716.522Path traversal
CVE-2026-1043358.8284Access-control execution flaw

Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…

1 hour ago

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8,…

3 hours ago

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…

3 hours ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…

3 hours ago

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…

4 hours ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…

5 hours ago