
[CIVN-2026-0407] Remote Code Execution Vulnerability in Langflow OSS
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Remote Code Execution Vulnerability in Langflow OSS
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Software Affected
Langflow OSS 1.0.0 through 1.10.0
Overview
A remote code execution vulnerability has been reported in Langflow OSS, which could allow an unauthenticated remote attacker to execute arbitrary code on the affected system.
Target Audience:
All organizations and individuals using Langflow OSS.
Risk Assessment:
Critical risk of arbitrary code execution, which could lead to complete compromise of the affected Langflow instance and the underlying system.
Impact Assessment:
Remote unauthenticated exploitation may lead to complete system compromise.
Description
Langflow OSS is an open-source platform for building and deploying AI-powered workflows and applications.
An unauthenticated remote code execution vulnerability exists in Langflow OSS due to improper authentication and unsafe handling of user-supplied Python code. Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to obtain a SUPERUSER bearer token through the auto-login endpoint and subsequently execute arbitrary Python code on the affected Langflow server through the code validation endpoint. The attacker may thereby execute arbitrary commands with the privileges of the Langflow process.
According to the vendor, the vulnerability affects default deployments where the auto-login feature is enabled and the validation endpoint is network-accessible. Successful exploitation could allow an attacker to compromise the confidentiality, integrity, and availability of the affected system.
Solution
Apply appropriate security updates and mitigations as recommended by the vendor.
https://www.ibm.com/support/pages/node/7278927
Vendor Information
IBM Corporation
https://www.ibm.com/
References
https://www.ibm.com/support/pages/node/7278927
CVE Name
CVE-2026-9198
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmp8gA4ACgkQ3jCgcSdc
ys/TrA//TsD3F76B8je6Q60fikOx7QswjJpqKGm1kBWc9Nz8vwOlpZfGYG+g9ULx
xbk+WqWqu9v9N5FrSQEJqBEwiM8NviszKw9QG6YFznDzS9saWN2czZ0Ev5EUXDQt
+Yh+5WCHOsjSQ5kj7D1R77CuB/scz8EYvY+zN2zJVxyuln66j+DAIq7crdnKr4gd
cD5Sy9adKwm2eT4NPxmwK8uax+saSzb5/IFkg2O7+xyDGIxdo6Y0kABpuhf4NJhA
07Lhi6DPi7c3FKDp+q92dGJSKaLYt6BHwdnQYcIRqH18YAs6KEDFN2NdRTxvYw0b
p2RyV68jnVoNlYBafaHuN5+QZPyzT5JlYkDrGmhqYVXpuBMnyUOXRe6z7ubKptl8
ypwmAO3vDKk1PObJ/MxdEEhR32RO7RC/2W/sXznyeVBZ9xJNpB0GOfw9QsIFrNBV
UaIbKWhLPJjDiLBD7EMsJrbc2YEGZwYPkEFD4ZI/xfiR2WPgHJut0en4gEWWmKjP
mW2xXHq+CyRZATdZvateq5w2CkFZd5uF8gm0FpZzsBxBmWhWFvNy9BPTEh4ZeZp0
rX1YWkSN9EV5hSc41RKu0qhwFurXLoK41p9s+oNJliKhxfoCpi0ZZbdcH7OPn3M0
U9rbMTTC1BHgr1zhv/3nRR/IVd6Ex2Pzdep1BnIlLJtqp69CY8g=
=jNsJ
—–END PGP SIGNATURE—–


