A security flaw has been identified in IBM Langflow, a low-code tool commonly used to build and manage custom AI workflows. This is a code injection vulnerability: attackers do not need any login credentials or pre-authorized access to exploit the flaw on default Langflow deployments. If successfully exploited, an attacker can run any code they choose on the server hosting the Langflow instance, giving them full, unrestricted control over that server. For users running Langflow on their hosting accounts, this could allow bad actors to access any data stored on the affected server, disrupt your Langflow services, or use the compromised server for additional malicious activity.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-9198