IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arbitrary code on the host system, resulting in complete compromise
PUBLISHED5.2ApplicationCWE-94
Unauthenticated Remote Code Execution in Langflow OSS PythonREPLComponent via Builtins Injection
Problem type
Affected products
IBM
Langflow OSS
<= 1.9.3 - AFFECTED
References
GitHub Security Advisories
GHSA-frvg-495w-m47v
IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python...
https://github.com/advisories/GHSA-frvg-495w-m47vIBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arbitrary code on the host system, resulting in complete compromise
JSON source
https://cveawg.mitre.org/api/cve/CVE-2026-10561Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-10561",
"assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
"assignerShortName": "ibm",
"dateUpdated": "2026-06-22T13:22:07.628Z",
"dateReserved": "2026-06-01T15:41:38.211Z",
"datePublished": "2026-06-22T13:22:07.628Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
"shortName": "ibm",
"dateUpdated": "2026-06-22T13:22:07.628Z"
},
"title": "Unauthenticated Remote Code Execution in Langflow OSS PythonREPLComponent via Builtins Injection",
"descriptions": [
{
"lang": "en",
"value": "IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arbitrary code on the host system, resulting in complete compromise",
"supportingMedia": [
{
"type": "text/html",
"base64": false,
"value": "<p>IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arbitrary code on the host system, resulting in complete compromise</p>"
}
]
}
],
"affected": [
{
"vendor": "IBM",
"product": "Langflow OSS",
"cpes": [
"cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*",
"cpe:2.3:a:ibm:langflow_oss:1.9.3:*:*:*:*:*:*:*"
],
"versions": [
{
"version": "1.0.0",
"status": "affected",
"versionType": "semver",
"lessThanOrEqual": "1.9.3"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "CWE-94 Improper Control of Generation of Code ('Code Injection')",
"cweId": "CWE-94",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://www.ibm.com/support/pages/node/7277242",
"tags": [
"vendor-advisory",
"patch"
]
}
],
"metrics": [
{
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
],
"cvssV3_1": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "CHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 10,
"baseSeverity": "CRITICAL"
}
}
],
"solutions": [
{
"lang": "en",
"value": "IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.9.4 https://pypi.org/project/langflow/",
"supportingMedia": [
{
"type": "text/html",
"base64": false,
"value": "<p>IBM strongly recommends addressing the vulnerability now by upgrading <a href=\"https://pypi.org/project/langflow/\" rel=\"nofollow\">Langflow OSS to version 1.9.4</a></p>"
}
]
}
]
}
}
}