A security flaw has been identified in IBM Langflow, a tool some users run on their web hosting accounts. This is a code injection vulnerability, a type of issue that lets attackers run their own arbitrary code on the affected system, and they do not need any login credentials to exploit it.
For default Langflow deployments, this flaw gives unauthenticated bad actors full remote control of the setup. This could allow them to access data stored in your Langflow instance, disrupt its normal operation, or repurpose the deployment for other harmful activity.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-9198