HIGH

CVE-2026-17632

Langflow Langflow 2026-08-05 CVSS v3.1
CVSS
8.8

Description

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of Python code during AST-based security scanning.

Summary dbcve.org

IBM Langflow versions 1.0.0 through 1.10.3 contains a vulnerability where the AST-based security scanning mechanism that validates Python code is improperly implemented, allowing an authenticated remote attacker to bypass the validation and execute arbitrary Python code on the system.

Mitigation

Upgrade IBM Langflow to a version beyond 1.10.3 that properly validates Python code within the AST-based security scanner to prevent code injection.

Weakness (CWE)

CWE-94 Code Injection

EPSS Score

0.61%
Probability of exploitation in next 30 days
47.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE