IBM Langflow: IBM Langflow Code Injection Vulnerability

  • Thursday, 6th August, 2026
  • 22:05pm

A code injection security flaw has been identified in the Langflow platform. This vulnerability allows unauthenticated attackers (people who do not have valid login credentials for the service) to run arbitrary code on servers running default, out-of-the-box Langflow deployments. This issue gives attackers full remote control of affected Langflow instances. If you use Langflow as part of your hosted website or services, this could allow bad actors to access, modify, or delete data tied to your Langflow setup, or use the underlying server for other malicious activity, all without needing to bypass your account security first.

Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-9198

« Back