CVE-2026-8635: Arbitrary Code Execution in Python Interpreter Component
IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute arbitrary system commands, and achieve full system compromise with Langflow service permissions.
Other sources
Langflow OSS allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute arbitrary system commands, and achieve full system compromise with Langflow service permissions.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Langflow OSSto a version that resolves this vulnerability.Fixed in 1.10.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8635?
The severity of CVE-2026-8635 is critical with a CVSS score of 9.9.
How do I fix CVE-2026-8635?
To fix CVE-2026-8635, upgrade IBM Langflow OSS to the latest version that addresses this vulnerability.
What type of attack does CVE-2026-8635 allow?
CVE-2026-8635 allows authenticated users to execute arbitrary code and escalate privileges to superuser.
Who is affected by CVE-2026-8635?
CVE-2026-8635 affects users of IBM Langflow OSS versions 1.0.0 through 1.10.0.
What is the impact of CVE-2026-8635?
The impact of CVE-2026-8635 includes full system compromise through the execution of arbitrary system commands.