CVE-2026-17625: Langflow is affected by OS Command Injection in Model Context Protocol features
IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
Other sources
Langflow OSS could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Langflow OSSto a version that resolves this vulnerability.Fixed in 1.11.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-17625?
CVE-2026-17625 has a severity rating of high, specifically 8.8.
What type of vulnerability is CVE-2026-17625?
CVE-2026-17625 is classified as an OS Command Injection vulnerability.
How do I fix CVE-2026-17625?
To fix CVE-2026-17625, upgrade IBM Langflow OSS to a version that addresses this vulnerability.
Can CVE-2026-17625 be exploited remotely?
Yes, CVE-2026-17625 can be exploited by a remote authenticated attacker.
What versions of IBM Langflow OSS are affected by CVE-2026-17625?
CVE-2026-17625 affects IBM Langflow OSS versions 1.0.0 through 1.10.3.