CVE-2026-93445: Langflow OSS is affected by multiple vulnerabilities
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper control of generation of code.
Other sources
Langflow OSS could allow a remote authenticated attacker to execute arbitrary code due to improper control of generation of code.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Langflow OSSto a version that resolves this vulnerability.Fixed in 1.12.3
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attacker must be remotely authenticated and have at least low-level privileges. No user interaction is required.
What is the potential impact if exploitation succeeds?
A successful attacker could execute arbitrary code, with high impact to confidentiality and integrity. The supplied vector indicates no direct availability impact.
Which releases are identified as affected?
IBM Langflow OSS versions 1.0.0 through 1.12.2 are identified as affected.