CVE-2026-78571: Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards
Published Sep 8, 2026
·Updated
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an unguarded eval() call on attacker-controlled input.
Other sources
Langflow OSS could allow a remote authenticated attacker to execute arbitrary code due to an unguarded eval() call on attacker-controlled input.
— IBM
Affected Software
1 affected component
IBM Langflow OSS<=1.0.0-1.11.5
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Langflow OSSto a version that resolves this vulnerability.Fixed in 1.11.6
Event History
Sep 8, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Sep 10, 2026
CVE Published
via MITRE·09:42 PM
Data Sourced
via MITRE·09:42 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attacker must be remotely authenticated. The available information does not indicate that unauthenticated users can exploit it.
2
What is the potential impact if exploitation succeeds?
A successful attacker could execute arbitrary code in the affected IBM Langflow OSS environment.