CVE-2026-12946: Remote Code Execution in CUGA Component CodeAgent
IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input code.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Langflow OSSto a version that resolves this vulnerability.Fixed in 1.10.1 - Compensating control
Until upgraded, mitigate remote exploitation of the Remote Code Execution (CUGA Component CodeAgent) by restricting network access to the Langflow instance to trusted sources only (e.g., via firewall/ACL).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12946?
The severity of CVE-2026-12946 is rated as critical with a score of 9.9.
How do I fix CVE-2026-12946?
To address CVE-2026-12946, update IBM Langflow OSS to the latest version that resolves this vulnerability.
What kind of attack can exploit CVE-2026-12946?
CVE-2026-12946 can be exploited through remote code execution, allowing attackers to inject arbitrary code.
Which versions of IBM Langflow OSS are affected by CVE-2026-12946?
IBM Langflow OSS versions 1.0.0 through 1.10.0 are affected by CVE-2026-12946.
What impact does CVE-2026-12946 have on a system?
CVE-2026-12946 can lead to a complete compromise of the affected system due to arbitrary code execution.