CVE-2026-97673: Langflow OSS is affected by multiple vulnerabilities
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper input validation.
Other sources
Langflow OSS could allow a remote authenticated attacker to execute arbitrary code due to improper input validation.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Langflow OSSto a version that resolves this vulnerability.Fixed in 1.12.3
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote attacker who is authenticated to IBM Langflow OSS can exploit it. The provided CVSS vector indicates low privileges are sufficient and no user interaction is required.
What versions are affected?
IBM Langflow OSS versions 1.0.0 through 1.12.2 are identified as affected.
What is the potential impact of successful exploitation?
Successful exploitation could allow arbitrary code execution. The CVSS vector indicates high impacts to confidentiality, integrity, and availability.