Unrated severityNVD Advisory· Published Jul 17, 2026· Updated Jul 23, 2026
Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints
CVE-2026-13448
Description
IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution vulnerability in the public flow build endpoint ( /api/v1/build_public_tmp/{flow_id}/flow ). The vulnerability stems from an incomplete denylist in the validate_public_flow_no_code_execution() function that fails to block several code-execution agent components including OpenDsStarAgent, CodeActAgentSmolagents, and CSVAgent.
Affected products
1- Range: 1.0.0 - 1.10.1
Patches
Vulnerability mechanics
References
1- www.ibm.com/support/pages/node/7279997mitrevendor-advisorypatch
News mentions
0No linked articles in our index yet.