CVE-2026-10134: Unauthenticated Server-Side RCE via PythonCodeStructuredTool in Public Flows
IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process, read and modify every flow, conversation, message, file upload, and saved component in the Langflow database, can connect to internal services, abuse cloud metadata endpoints, laterally move to other tenants on the same Langflow instance, and Establish persistence by modifying the public flow's toolcode so normal /api/v1/build/... calls by any user re-execute attacker code at each build.
Other sources
Langflow OSS allows an attacker to read every secret available to the Langflow process, read and modify every flow, conversation, message, file upload, and saved component in the Langflow database, can connect to internal services, abuse cloud metadata endpoints, laterally move to other tenants on the same Langflow instance, and Establish persistence by modifying the public flow's toolcode so normal /api/v1/build/... calls by any user re-execute attacker code at each build.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Langflow OSSto a version that resolves this vulnerability.Fixed in 1.10.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10134?
CVE-2026-10134 has a severity rating of critical with a score of 10.
How do I fix CVE-2026-10134?
To fix CVE-2026-10134, upgrade to a patched version of IBM Langflow OSS beyond 1.9.3.
What types of attacks are possible with CVE-2026-10134?
CVE-2026-10134 allows unauthenticated remote code execution, enabling attackers to read and modify data in the Langflow database.
What versions of Langflow OSS are affected by CVE-2026-10134?
CVE-2026-10134 affects IBM Langflow OSS versions 1.0.0 through 1.9.3.
What are the impacts of CVE-2026-10134?
The impacts of CVE-2026-10134 include unauthorized access to secrets, modification of flows, and potential lateral movement within internal services.