info: name: langflow author: A.I.G bot cve: CVE-2026-12946 summary: langflow IBM Langflow OSS 1 details: IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input code. The vulnerability arises because user-supplied code input is not adequately validated or sandboxed before being executed within the Langflow server process. An authenticated remote attacker with low privileges can craft malicious code payloads that are processed and executed by the application, leading to arbitrary code execution with the privileges of the Langflow server process. Successful exploitation can result in complete system compromise, including confidentiality, integrity, and availability impact across the security boundary. cvss: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H severity: CRITICAL security_advise: Upgrade langflow to version 1.10.1 or later. rule: version >= "1.0.0" && version <= "1.10.0" references: - https://www.ibm.com/support/pages/node/7278928