VYPR
Vypr IntelligenceAI-generatedOct 7, 2026· 24 CVEs

IBM Langflow OSS: 24 Critical Vulnerabilities Disclosed in Coordinated October 7th Batch

IBM's Langflow OSS faces a critical security event with 24 vulnerabilities disclosed on October 7, 2026, enabling RCE and data leaks in versions 1.0.0-1.12.2.

Key findings

  • 24 vulnerabilities disclosed for IBM Langflow OSS on October 7, 2026, affecting versions 1.0.0 through 1.12.2.
  • Multiple critical and high-severity flaws allow for remote code execution and sensitive information disclosure.
  • Key issues include improper input validation, code injection, and access control weaknesses.
  • CVE-2026-93674 and CVE-2026-104334 are rated Critical (CVSSv3 9.8) for arbitrary code execution.
  • Vulnerabilities range from RCE and data leaks to denial of service via resource exhaustion.
  • Users must update to the latest version to mitigate these widespread security risks.

On October 7, 2026, a significant batch of 24 vulnerabilities was disclosed for IBM's Langflow OSS, affecting versions 1.0.0 through 1.12.2. This coordinated disclosure event highlights critical security weaknesses within the platform, with many flaws allowing for remote code execution and sensitive information disclosure. The vulnerabilities stem from various issues including improper input validation, insufficient access controls, and inadequate neutralization of special elements in code and OS commands.

A primary theme across these vulnerabilities is the potential for remote code execution (RCE). Multiple CVEs, including CVE-2026-97679, CVE-2026-97678, CVE-2026-97676, CVE-2026-97673, CVE-2026-97655, CVE-2026-93675, CVE-2026-93674, CVE-2026-93448, CVE-2026-93447, CVE-2026-93445, CVE-2026-93443, CVE-2026-88962, CVE-2026-104334, and CVE-2026-104335, detail RCE possibilities due to improper input validation, code generation control, or neutralization of special elements in OS commands. Specifically, CVE-2026-93674 and CVE-2026-104334 are rated Critical (CVSSv3 9.8), indicating a severe risk of arbitrary code execution. CVE-2026-97679 and CVE-2026-97676 also mention 'Code Injection' and 'sandbox escape' respectively, underscoring the severity of these flaws.

Another significant category of vulnerabilities involves the potential for remote authenticated attackers to obtain sensitive information. CVE-2026-97680, CVE-2026-97671, CVE-2026-93678, CVE-2026-93677, CVE-2026-93449, CVE-2026-93448, CVE-2026-103360, CVE-2026-101331, and CVE-2026-101329 all fall into this group. These range from improper access control and path traversal issues (CVE-2026-97671, CVE-2026-93448, CVE-2026-103360) to insufficient credential protection (CVE-2026-101331) and improper authorization (CVE-2026-93678).

The batch also includes vulnerabilities related to improper control of code generation and specific attack vectors. CVE-2026-93449 and CVE-2026-93445 highlight issues with improper control of code generation, while CVE-2026-97674 specifically mentions 'Code Injection' via OS commands. CVE-2026-93447 describes a scenario where a malicious serialized cache value could lead to code execution upon deserialization, requiring server secret access and Redis write access. Additionally, CVE-2026-97655 points to an incomplete blocklist in the code security scanner, and CVE-2026-93675 notes an issue related to dependency confusion.

Denial of Service (DoS) is also a concern, with CVE-2026-93679 detailing uncontrolled resource consumption during ZIP file extraction, allowing a remote authenticated attacker to cause a DoS.

All disclosed vulnerabilities affect IBM Langflow OSS versions 1.0.0 through 1.12.2. While specific patch versions are not detailed in the provided information, users are strongly advised to update to the latest available version to mitigate these risks. The sheer volume and severity of these vulnerabilities, disclosed simultaneously, indicate a critical need for users to review their Langflow OSS deployments and apply necessary security updates promptly.

The coordinated disclosure of these 24 vulnerabilities on October 7, 2026, presents a significant security challenge for users of IBM Langflow OSS. The prevalence of RCE and sensitive data exposure flaws necessitates immediate attention from administrators. Organizations relying on Langflow OSS should prioritize updating to patched versions and review their security configurations to prevent potential exploitation. The broad range of affected versions (1.0.0 through 1.12.2) means a substantial user base is potentially at risk.

Key findings from this batch include:

  • A Critical (CVSSv3 9.8) vulnerability, CVE-2026-93674, allows remote attackers to execute arbitrary code.
  • Multiple high-severity vulnerabilities (CVSSv3 8.8) exist, including RCE via code injection and sandbox escapes.
  • A significant number of CVEs focus on sensitive information disclosure due to access control and path traversal flaws.
  • Denial of Service is possible through uncontrolled resource consumption during file extraction (CVE-2026-93679).
  • All disclosed vulnerabilities affect Langflow OSS versions 1.0.0 through 1.12.2.
  • The batch includes issues related to code generation, dependency confusion, and deserialization vulnerabilities.
  • The vulnerabilities were disclosed in a single, coordinated event on October 7, 2026.
  • Remote code execution is a primary risk across many of the disclosed flaws.
AI-written article. Grounded in 24 CVE records listed below.