CVE-2026-10561
IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arbitrary code on the host system, resulting in complete compromise
View on NVDAnalysis
IBM Langflow OSS en sus versiones 1.0.0 a 1.9.3 presenta una vulnerabilidad crítica que permite a atacantes no autenticados ejecutar código arbitrario de Python en el servidor mediante un bypass de autenticación. Esto otorga control total sobre el sistema operativo anfitrión, comprometiendo la infraestructura de IA desplegada. Se recomienda actualizar de inmediato para mitigar el riesgo de ejecución remota de código.
Relevant roles
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HCWE-94EPSS
No EPSS score yet (CVE may be too fresh).
Technical description
IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arbitrary code on the host system, resulting in complete compromise