Multiple vulnerabilities in IBM Langflow OSS 1.0.0-1.11.5
IBM Langflow OSS versions 1.0.0 through 1.11.5 contain multiple vulnerabilities allowing remote authenticated attackers to execute arbitrary Python code, OS commands, and access sensitive information due to improper authorization, insufficient session expiration, and pathname restrictions.
Disclosed 11 September 2026 · Record updated 13 September 2026
Impact
Remote authenticated attackers can execute arbitrary Python and OS commands, obtain sensitive information including credentials, modify files, and potentially move laterally to other services.
Our coverage
No articles linked to this incident yet.
Sources
- github.comhttps://github.com/advisories/GHSA-j99h-p584-x29h
- github.comhttps://github.com/advisories/GHSA-m6qv-7wcf-v4qx
- github.comhttps://github.com/advisories/GHSA-2fpx-w7mw-jhxj
- github.comhttps://github.com/advisories/GHSA-m5q4-pf3r-r78g
- github.comhttps://github.com/advisories/GHSA-8m33-2h4q-m779
