CVE-2026-10561: Unauthenticated Remote Code Execution in Langflow OSS PythonREPLComponent via Builtins Injection
IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arbitrary code on the host system, resulting in complete compromise
Other sources
Langflow OSS has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arbitrary code on the host system, resulting in complete compromise
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Langflow OSSto a version that resolves this vulnerability.Fixed in 1.9.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10561?
CVE-2026-10561 has a severity rating of 10, indicating a critical vulnerability.
How does CVE-2026-10561 affect IBM Langflow OSS?
CVE-2026-10561 allows an unauthenticated attacker to execute arbitrary code on the host system, leading to complete compromise.
What versions of IBM Langflow OSS are vulnerable to CVE-2026-10561?
IBM Langflow OSS versions 1.0.0 through 1.9.3 are affected by CVE-2026-10561.
How can I fix CVE-2026-10561?
To mitigate CVE-2026-10561, it is recommended to upgrade to a version of IBM Langflow OSS that is not vulnerable.
What type of attack does CVE-2026-10561 enable?
CVE-2026-10561 enables unauthenticated remote code execution due to builtins injection.