CVE-2026-93449: Langflow OSS is affected by multiple vulnerabilities
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper control of code generation.
Other sources
Langflow OSS could allow a remote authenticated attacker to execute arbitrary code due to improper control of code generation.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Langflow OSSto a version that resolves this vulnerability.Fixed in 1.12.3
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote attacker who is authenticated to IBM Langflow OSS could exploit it. The attacker must have at least low-level privileges; no user interaction is required.
What is the potential impact of successful exploitation?
Successful exploitation could allow arbitrary code execution. The listed impacts include high confidentiality, integrity, and availability impact, and the scope may extend beyond the vulnerable component.
Which versions should be investigated?
IBM Langflow OSS versions 1.0.0 through 1.12.2 are identified as affected. The provided information does not state which version, if any, contains a fix.