[CIVN-2026-0407] Remote Code Execution Vulnerability in Langflow OSS

By Published On: August 12, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Remote Code Execution Vulnerability in Langflow OSS


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: CRITICAL


Software Affected


Langflow OSS 1.0.0 through 1.10.0

Overview


A remote code execution vulnerability has been reported in Langflow OSS, which could allow an unauthenticated remote attacker to execute arbitrary code on the affected system.


Target Audience:

All organizations and individuals using Langflow OSS.


Risk Assessment:

Critical risk of arbitrary code execution, which could lead to complete compromise of the affected Langflow instance and the underlying system.


Impact Assessment:

Remote unauthenticated exploitation may lead to complete system compromise.


Description


Langflow OSS is an open-source platform for building and deploying AI-powered workflows and applications.


An unauthenticated remote code execution vulnerability exists in Langflow OSS due to improper authentication and unsafe handling of user-supplied Python code. Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to obtain a SUPERUSER bearer token through the auto-login endpoint and subsequently execute arbitrary Python code on the affected Langflow server through the code validation endpoint. The attacker may thereby execute arbitrary commands with the privileges of the Langflow process.


According to the vendor, the vulnerability affects default deployments where the auto-login feature is enabled and the validation endpoint is network-accessible. Successful exploitation could allow an attacker to compromise the confidentiality, integrity, and availability of the affected system.


Solution


Apply appropriate security updates and mitigations as recommended by the vendor.

https://www.ibm.com/support/pages/node/7278927



Vendor Information


IBM Corporation

https://www.ibm.com/


References


 

https://www.ibm.com/support/pages/node/7278927


CVE Name

CVE-2026-9198




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmp8gA4ACgkQ3jCgcSdc

ys/TrA//TsD3F76B8je6Q60fikOx7QswjJpqKGm1kBWc9Nz8vwOlpZfGYG+g9ULx

xbk+WqWqu9v9N5FrSQEJqBEwiM8NviszKw9QG6YFznDzS9saWN2czZ0Ev5EUXDQt

+Yh+5WCHOsjSQ5kj7D1R77CuB/scz8EYvY+zN2zJVxyuln66j+DAIq7crdnKr4gd

cD5Sy9adKwm2eT4NPxmwK8uax+saSzb5/IFkg2O7+xyDGIxdo6Y0kABpuhf4NJhA

07Lhi6DPi7c3FKDp+q92dGJSKaLYt6BHwdnQYcIRqH18YAs6KEDFN2NdRTxvYw0b

p2RyV68jnVoNlYBafaHuN5+QZPyzT5JlYkDrGmhqYVXpuBMnyUOXRe6z7ubKptl8

ypwmAO3vDKk1PObJ/MxdEEhR32RO7RC/2W/sXznyeVBZ9xJNpB0GOfw9QsIFrNBV

UaIbKWhLPJjDiLBD7EMsJrbc2YEGZwYPkEFD4ZI/xfiR2WPgHJut0en4gEWWmKjP

mW2xXHq+CyRZATdZvateq5w2CkFZd5uF8gm0FpZzsBxBmWhWFvNy9BPTEh4ZeZp0

rX1YWkSN9EV5hSc41RKu0qhwFurXLoK41p9s+oNJliKhxfoCpi0ZZbdcH7OPn3M0

U9rbMTTC1BHgr1zhv/3nRR/IVd6Ex2Pzdep1BnIlLJtqp69CY8g=

=jNsJ

—–END PGP SIGNATURE—–

Share this article