TL;DR
IBM has published a security bulletin covering 25 Langflow vulnerabilities in Langflow OSS versions 1.0.0 through 1.12.2. Two flaws, CVE-2026-104334 and CVE-2026-93674, score 9.8 on CVSS 3.1 and let an unauthenticated attacker run code. IBM urges users to upgrade to Langflow 1.12.3.
Too many alerts in your inbox? Switch to one weekly digest, sorted by severity.
Try Team free for 14 daysWhy It Matters
Langflow is an open-source tool for building AI agents and LLM workflows. Its servers often hold API keys, database credentials and model secrets. As a result, a takeover could expose far more than the Langflow host itself.
The batch is heavy. Of the 25 flaws, 2 are critical, 19 are high and 4 are medium. In total, 15 can lead to code execution. IBM’s bulletin does not report exploitation in the wild, and no public proof-of-concept has been confirmed.
How the Attacks Work
Unauthenticated Code Execution
CVE-2026-104334 stems from “improper control of code generation,” while CVE-2026-93674 involves “improper neutralization of special elements used in an OS command.” Both need no login and no user interaction.
A third flaw, CVE-2026-93675 (CVSS 8.8), abuses dependency confusion. It also needs no login, though a user must take an action.
Sandbox Escapes for Logged-In Users
Most of the other Langflow vulnerabilities target authenticated users. Several bypass the platform’s code security checks. For example, CVE-2026-97655 slips past “an incomplete blocklist in the code security scanner.” CVE-2026-97676 enables a sandbox escape. Meanwhile, CVE-2026-93447 abuses deserialization of cached Redis values, but it requires the server secret and Redis write access.
File Access and Data Leaks
Path traversal bugs let users read or write files outside allowed folders. According to IBM, CVE-2026-97677 lets a flow author write files “into any directory writable by the service account.” It can also read “configuration files, secrets, or database files.” Other bugs leak credentials or poison the vertex result cache. Finally, CVE-2026-93679 crashes the server with oversized ZIP archives.
Affected Versions
All 25 flaws affect Langflow OSS 1.0.0 through 1.12.2.
Patch and Mitigation Steps
Upgrade to Langflow 1.12.3 right away. IBM “strongly recommends addressing the vulnerability now.” Full details sit in the IBM security bulletin for Langflow OSS.
Until the upgrade is done, keep Langflow off the public internet. Limit who can create or edit flows, since most of these Langflow vulnerabilities need an account. After patching, rotate any API keys and credentials stored in the platform.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!