CVE-2026-97655: Langflow OSS is affected by multiple vulnerabilities
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to an incomplete blocklist in the code security scanner.
Other sources
Langflow OSS could allow a remote attacker to execute arbitrary code due to an incomplete blocklist in the code security scanner.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Langflow OSSto a version that resolves this vulnerability.Fixed in 1.12.3
Event History
Frequently Asked Questions
Which deployments are in the affected version range?
IBM Langflow OSS versions 1.0.0 through 1.12.2 are identified as affected.
What level of access does an attacker need?
The CVSS vector indicates network-reachable exploitation with low privileges required and no user interaction. The attack complexity is rated low.
What is the potential impact of successful exploitation?
A remote attacker could execute arbitrary code. The vulnerability is rated high severity with high potential impact to confidentiality, integrity, and availability.