Unrated severityNVD Advisory· Published Jul 17, 2026· Updated Jul 23, 2026
Arbitrary Code Execution in Python Interpreter Component
CVE-2026-8635
Description
IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute arbitrary system commands, and achieve full system compromise with Langflow service permissions.
Affected products
1- Range: 1.0.0 - 1.10.0
Patches
Vulnerability mechanics
References
1- www.ibm.com/support/pages/node/7278925mitrevendor-advisorypatch
News mentions
0No linked articles in our index yet.