CVE-2026-17633: Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling
IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to code injection.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Langflow OSSto a version that resolves this vulnerability.Fixed in 1.11.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-17633?
CVE-2026-17633 has a risk score of 77, indicating a high severity level.
How do I fix CVE-2026-17633?
To remediate CVE-2026-17633, update to the latest version of IBM Langflow OSS that addresses the code injection vulnerability.
What type of vulnerability is CVE-2026-17633?
CVE-2026-17633 is classified as a code injection vulnerability.
Who is affected by CVE-2026-17633?
CVE-2026-17633 affects users of IBM Langflow OSS who may be susceptible to remote code execution by authenticated attackers.
What impact does CVE-2026-17633 have?
CVE-2026-17633 enables remote authenticated attackers to execute arbitrary code on affected systems.