CVE-2026-14499: Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints
IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input in the Python Interpreter component.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Langflow OSSto a version that resolves this vulnerability.Fixed in 1.10.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14499?
The severity of CVE-2026-14499 is high with a score of 8.8.
How do I fix CVE-2026-14499?
To fix CVE-2026-14499, ensure that you update to the latest patched version of IBM Langflow OSS that addresses these vulnerabilities.
What types of vulnerabilities are associated with CVE-2026-14499?
CVE-2026-14499 involves remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints.
Who is affected by CVE-2026-14499?
CVE-2026-14499 affects users of IBM Langflow OSS versions 1.0.0 through 1.10.1.
What can attackers achieve using CVE-2026-14499?
Attackers can exploit CVE-2026-14499 to execute arbitrary commands with elevated privileges on the system.