IBMCVE-2026-17624
IBM Langflow OSS: remote code execution
High8.5CVE-2026-17624 · Published Aug 5, 2026 · updated Aug 6, 2026
IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of module imports.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Langflow OSS Product | >= 1.0.0, <= 1.10.3 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-94
More IBM advisories
All IBM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 5 | IBM Langflow OSS: weak cryptography | High7.4 | No fix yet |
| Aug 5 | IBM Langflow OSS: code injection | High8.1 | No fix yet |
| Aug 5 | IBM Langflow OSS: code execution | High8.8 | No fix yet |
| Aug 5 | IBM Langflow OSS: information disclosure | High7.1 | No fix yet |
| Aug 5 | IBM Langflow OSS: code injection | High8.8 | No fix yet |
| Aug 5 | IBM Langflow OSS: broken cryptography | High7.4 | No fix yet |