A critical security vulnerability has been discovered in IBM Langflow, a tool some users run on their web hosting accounts. This flaw allows unauthenticated attackers (people without login access to the tool) to execute their own malicious code on default Langflow deployments, giving them full remote control over the system hosting the tool.
If you have Langflow installed on your hosted account, this could allow an attacker to access, modify, or delete your website and stored data, or misuse your hosting resources for harmful activity without your knowledge. Users who do not run Langflow on their accounts are not affected by this flaw.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-9198