CVE-2026-18729: Langflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcement
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitrary code due to improper control of generation of code.
Other sources
Langflow OSS could allow a remote authenticated attacker to execute arbitrary code due to improper control of generation of code.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Langflow OSSto a version that resolves this vulnerability.Fixed in 1.11.2
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
An attacker must be remotely authenticated to exploit it. No user interaction is required.
Which deployments are known to be affected?
IBM Langflow OSS versions 1.0.0 through 1.11.1 are affected. The provided information does not specify any configuration-dependent limitations.
What is the potential impact of successful exploitation?
A successful attacker can execute arbitrary code. The listed severity vector indicates high impact to confidentiality, integrity, and availability.