Skip to content
CVSS 10.0CVSS 10.0 · CRITICAL

CVE-2026-10561

IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arbitrary code on the host system, resulting in complete compromise

View on NVD

Analysis

IBM Langflow OSS en sus versiones 1.0.0 a 1.9.3 presenta una vulnerabilidad crítica que permite a atacantes no autenticados ejecutar código arbitrario de Python en el servidor mediante un bypass de autenticación. Esto otorga control total sobre el sistema operativo anfitrión, comprometiendo la infraestructura de IA desplegada. Se recomienda actualizar de inmediato para mitigar el riesgo de ejecución remota de código.

Relevant roles

IAPythonDataScienceMachineLearningBackendCyberSecurity

Severity

Score: 10.0(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE): CWE-94

EPSS

No EPSS score yet (CVE may be too fresh).

Technical description

IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arbitrary code on the host system, resulting in complete compromise

Published: 6/22/2026, 2:16:25 PM
Last modified: 6/22/2026, 2:16:25 PM

References

HomeEventsBlogResourcesTeam