High severity8.1NVD Advisory· Published Oct 7, 2026
CVE-2026-97674
CVE-2026-97674
Description
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command ('Code Injection'), aka improper control of code generation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: 1.0.0 - 1.12.2
Patches
Vulnerability mechanics
References
1News mentions
1- IBM Langflow OSS: 24 Critical Vulnerabilities Disclosed in Coordinated October 7th BatchVypr Intelligence · Oct 7, 2026