CVE-2026-8478: Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling
IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input code.
Other sources
Langflow OSS could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input code.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Langflow OSSto a version that resolves this vulnerability.Fixed in 1.11.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8478?
CVE-2026-8478 has a high severity rating of 8.8.
How do I fix CVE-2026-8478?
To fix CVE-2026-8478, upgrade IBM Langflow OSS to a version beyond 1.10.3.
What type of vulnerability is CVE-2026-8478?
CVE-2026-8478 is an arbitrary code execution vulnerability stemming from improper control of user input code.
What software is affected by CVE-2026-8478?
CVE-2026-8478 affects IBM Langflow OSS versions 1.0.0 to 1.10.3.
What are the potential impacts of CVE-2026-8478?
Exploitation of CVE-2026-8478 could allow a remote attacker to execute arbitrary code on the affected system.