CVE-2026-10547: Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement
IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate ownership in the deprecated POST /api/v1/build/{flowid}/vertices endpoint, allowing an authenticated user to inject arbitrary graph data into a shared cache for any flow. This may result in cross-user cache pollution, unauthorized workflow execution, or denial of service.
Other sources
Langflow OSS does not properly validate ownership in the deprecated POST /api/v1/build/{flowid}/vertices endpoint, allowing an authenticated user to inject arbitrary graph data into a shared cache for any flow. This may result in cross-user cache pollution, unauthorized workflow execution, or denial of service.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Langflow OSSto a version that resolves this vulnerability.Fixed in 1.11.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10547?
The severity of CVE-2026-10547 is medium with a score of 5.9.
How do I fix CVE-2026-10547?
To fix CVE-2026-10547, update to a patched version of IBM Langflow OSS that correctly validates ownership.
What type of vulnerability is CVE-2026-10547?
CVE-2026-10547 is an arbitrary code execution vulnerability in custom component validation.
What impact does CVE-2026-10547 have?
CVE-2026-10547 may lead to cross-user cache pollution and unauthorized workflow manipulation.
Who is affected by CVE-2026-10547?
CVE-2026-10547 affects users of IBM Langflow OSS versions 1.0.0 through 1.10.3.