IBM Langflow OSS code injection via ToolGuard integration
IBM Langflow OSS versions 1.0.0 through 1.10.0 contain a code injection vulnerability in the ToolGuard component that allows authenticated users to bypass custom component restrictions and achieve arbitrary Python code execution on the backend.
Disclosed 17 July 2026 · Record updated 13 September 2026
Impact
Authenticated users with flow creation privileges can execute arbitrary Python code on the backend, with potential for cross-tenant escalation via the MCP update_flow_component_field tool.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-9135
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-14501
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-15995
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-7755
