IBM Langflow: IBM Langflow Code Injection Vulnerability

  • Thursday, 6th August, 2026
  • 04:04am

A security vulnerability has been identified in IBM Langflow. The flaw is a code injection issue that impacts default, unmodified Langflow deployments. It allows unauthenticated attackers (people who do not have login credentials for your Langflow setup) to run any code they want on the server where Langflow is installed, giving them full remote control of that system. This

Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-9198

« Back