CVE-2026-8182: Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling
IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on the server without any credentials via 2 HTTP requests.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Langflow OSSto a version that resolves this vulnerability.Fixed in 1.11.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8182?
CVE-2026-8182 has a risk score of 97, indicating a critical vulnerability in IBM Langflow OSS.
What software is affected by CVE-2026-8182?
CVE-2026-8182 affects IBM Langflow OSS installations.
How can an attacker exploit CVE-2026-8182?
An attacker can exploit CVE-2026-8182 by sending two specific HTTP requests to execute arbitrary code on the server.
What are the potential consequences of CVE-2026-8182?
The potential consequences of CVE-2026-8182 include unauthorized code execution, which can lead to a complete compromise of the affected system.
How do I mitigate CVE-2026-8182?
To mitigate CVE-2026-8182, it is essential to apply security patches and restrict access to vulnerable server instances.