CVE-2026-93443: Langflow OSS is affected by multiple vulnerabilities
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in code.
Other sources
Langflow OSS could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in code.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Langflow OSSto a version that resolves this vulnerability.Fixed in 1.12.3
Event History
Frequently Asked Questions
Which deployments are affected?
IBM Langflow OSS versions 1.0.0 through 1.12.2 are affected.
What access does an attacker need to exploit this issue?
An attacker must be remote and authenticated. The CVSS vector indicates low privileges are required and no user interaction is needed, although exploitation has high attack complexity.
What could successful exploitation allow?
Successful exploitation could allow arbitrary code execution, with high potential impact to confidentiality, integrity, and availability.