CVE-2026-8182
Description
IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on the server without any credentials via 2 HTTP requests.
Summary dbcve.org
IBM Langflow OSS versions 1.0.0 through 1.10.3 contain a critical authentication bypass vulnerability that allows unauthenticated remote attackers to execute arbitrary code on the server through only two HTTP requests. The vulnerability appears to stem from a flaw in the authentication mechanism that can be bypassed without any credentials.
Mitigation
Immediately upgrade to the latest version of IBM Langflow OSS past 1.10.3. If immediate patching is not possible, restrict network access to the Langflow service using network segmentation or firewall rules to prevent unauthorized internet access.