CVE-2026-7873: Code Injection Vulnerability in Code Validation Endpoint
IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated attackers to execute arbitrary OS commands and read sensitive files including credentials, enabling complete system compromise and lateral movement.
Other sources
Langflow OSS allows authenticated attackers to execute arbitrary OS commands and read sensitive files including credentials, enabling complete system compromise and lateral movement.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Langflow OSSto a version that resolves this vulnerability.Fixed in 1.10.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7873?
CVE-2026-7873 has a critical severity rating of 9.9.
How does CVE-2026-7873 affect IBM Langflow OSS?
CVE-2026-7873 allows authenticated attackers to execute arbitrary OS commands and read sensitive files.
What can be the impact of CVE-2026-7873 on a system?
The impact of CVE-2026-7873 includes complete system compromise and potential lateral movement within a network.
How can I mitigate CVE-2026-7873?
To mitigate CVE-2026-7873, ensure you upgrade to a secure version of IBM Langflow OSS above 1.10.0.
Who is affected by the CVE-2026-7873 vulnerability?
CVE-2026-7873 affects users of IBM Langflow OSS versions 1.0.0 through 1.10.0.