CVE-2026-13435: Python Interpreter Sandbox Bypass Leading to Sensitive Data Exposure
Published Jul 14, 2026
·Updated
IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox implementation.
Other sources
Langflow OSS contains an improper input validation vulnerability in the PythonREPL sandbox implementation.
— IBM
Affected Software
3 affected components
IBM Langflow OSS>=1.0.0<=1.10.1
IBM Langflow OSS<=1.0.0-1.10.1
Langflow Langflow>=1.0.0<1.10.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Langflow OSSto a version that resolves this vulnerability.Fixed in 1.10.2
Event History
Jul 14, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Jul 30, 2026
CVE Published
via MITRE·04:48 PM
Data Sourced
via MITRE·04:48 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-13435?
CVE-2026-13435 has a critical severity rating of 9.9.
2
How do I fix CVE-2026-13435?
To fix CVE-2026-13435, upgrade IBM Langflow OSS to version 1.10.2 or later.
3
What type of vulnerability is CVE-2026-13435?
CVE-2026-13435 is an improper input validation vulnerability leading to a sandbox bypass.
4
What are the potential impacts of CVE-2026-13435?
CVE-2026-13435 can lead to sensitive data exposure due to code injection.
5
Which versions of IBM Langflow OSS are affected by CVE-2026-13435?
CVE-2026-13435 affects IBM Langflow OSS versions 1.0.0 through 1.10.1.