CVE-2026-97679: Langflow OSS is affected by multiple vulnerabilities
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command ('Code Injection') related to improper input validation.
Other sources
Langflow OSS could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command ('Code Injection') related to improper input validation.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Langflow OSSto a version that resolves this vulnerability.Fixed in 1.12.3
Event History
Frequently Asked Questions
Which deployments are known to be affected?
IBM Langflow OSS versions 1.0.0 through 1.12.2 are identified as affected.
Does exploitation require authentication or user interaction?
An attacker must be remotely authenticated and have low privileges. No user interaction is required.
What level of impact could successful exploitation have?
Successful exploitation could allow arbitrary code execution and has high potential impact on confidentiality, integrity, and availability.