CVE-2026-17629: SQL Injection
Published Aug 5, 2026
·Updated
Langflow OSS is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
Affected Software
1 affected component
IBM Langflow OSS<=1.0.0-1.10.3
Event History
Aug 5, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-17629?
CVE-2026-17629 has a risk severity score of 71, indicating a high level of concern.
2
What type of vulnerability is CVE-2026-17629?
CVE-2026-17629 is classified as an SQL injection vulnerability.
3
How can an attacker exploit CVE-2026-17629?
An attacker can exploit CVE-2026-17629 by sending specially crafted SQL statements to the application.
4
What impact does CVE-2026-17629 have on IBM Langflow OSS?
CVE-2026-17629 allows attackers to view, add, modify, or delete information in the back-end database.
5
How can I fix CVE-2026-17629 in IBM Langflow OSS?
To fix CVE-2026-17629, you should apply the latest software updates and patches provided by IBM.