HIGH
CVE-2026-17632
CVSS
8.8
Description
IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of Python code during AST-based security scanning.
Summary dbcve.org
IBM Langflow versions 1.0.0 through 1.10.3 contains a vulnerability where the AST-based security scanning mechanism that validates Python code is improperly implemented, allowing an authenticated remote attacker to bypass the validation and execute arbitrary Python code on the system.
Mitigation
Upgrade IBM Langflow to a version beyond 1.10.3 that properly validates Python code within the AST-based security scanner to prevent code injection.
Weakness (CWE)
CWE-94
Code Injection
EPSS Score
0.61%
Probability of exploitation in next 30 days
47.7th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.