A serious security flaw has been found in IBM Langflow, a tool some website owners use to build and manage automated workflows on their hosting accounts. This is a code injection vulnerability, which allows unapproved users to run their own custom code on default Langflow setups.
The most concerning part of this flaw is that attackers do not need any login credentials or authorized access to exploit it. If you run Langflow on your hosting account, this vulnerability could let bad actors take complete control of your Langflow instance, access any data processed or stored by the tool, or use the service to carry out harmful activities without your knowledge.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-9198