HIGH

CVE-2026-8182

Langflow Langflow 2026-08-05 CVSS v3.1
CVSS
8.8

Description

IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on the server without any credentials via 2 HTTP requests.

Summary dbcve.org

IBM Langflow OSS versions 1.0.0 through 1.10.3 contain a critical authentication bypass vulnerability that allows unauthenticated remote attackers to execute arbitrary code on the server through only two HTTP requests. The vulnerability appears to stem from a flaw in the authentication mechanism that can be bypassed without any credentials.

Mitigation

Immediately upgrade to the latest version of IBM Langflow OSS past 1.10.3. If immediate patching is not possible, restrict network access to the Langflow service using network segmentation or firewall rules to prevent unauthorized internet access.

Weakness (CWE)

CWE-94 Code Injection

EPSS Score

0.38%
Probability of exploitation in next 30 days
32.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE