CVE-2026-97676: Langflow OSS is affected by multiple vulnerabilities
Published Oct 2, 2026
·Updated
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in code, resulting in a sandbox escape.
Other sources
Langflow OSS could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in code, resulting in a sandbox escape.
— IBM
Affected Software
2 affected components
IBM Langflow OSS<=1.0.0-1.12.2
Langflow Langflow>=1.0.0<1.12.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Langflow OSSto a version that resolves this vulnerability.Fixed in 1.12.3
Event History
Oct 2, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Oct 6, 2026
CVE Published
via MITRE·11:58 PM
Data Sourced
via MITRE·11:58 PM
RemedyDescriptionSeverityWeakness
Oct 7, 2026
Data Sourced
via NVD·01:16 AM
DescriptionSeverityWeaknessAffected Software
Oct 8, 2026
Event
via FIRST·02:34 PM
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attacker must be authenticated to Langflow OSS. The attack can be performed remotely over the network, requires low complexity, and does not require user interaction.