Vulnerability
Published 2026-10-02
Verified 2026-10-07

IBM Langflow OSS bulletin: 25 CVEs in Langflow 1.0.0 to 1.12.2, including two unauthenticated code-execution flaws (CVE-2026-104334 and CVE-2026-93674, CVSS 9.8); upgrade to 1.12.3 or later

IBM, which now acts as CVE numbering authority for Langflow OSS, published security bulletin 7290694 on 2 October 2026 covering 25 vulnerabilities in Langflow 1.0.0 through 1.12.2, the open-source visual builder for AI agents and workflows. The CVE records went public on 6 and 7 October. The two worst, CVE-2026-104334 (code injection) and CVE-2026-93674 (OS command injection), are rated 9.8 by IBM and need no login. Most of the rest need an authenticated user, which in Langflow usually means anyone who can build flows: several sandbox escapes and code-security-scanner bypasses that run code on the server (CVE-2026-97676, 97678, 97673, 97655, 97679, 88962, all 8.8), an OS command injection (CVE-2026-97674, 8.1), path traversal that writes files anywhere the service account can and reads configuration, secrets or database files (CVE-2026-97677, 8.1; CVE-2026-103360, 8.1), cross-user access to cached component results (CVE-2026-97680, 8.3), poorly protected stored credentials (CVE-2026-101331, 7.7), authorization bypasses (CVE-2026-93678, 7.6) and a ZIP extraction denial of service (CVE-2026-93679, 4.3). IBM lists no workarounds. This is a separate set from the Langflow MCP stdio flaws already on the desk (fixed in 1.10.3), so a 1.10.3 install is still exposed. IBM does not report exploitation, but earlier Langflow code-injection flaws were exploited within days of disclosure. Primary: IBM security bulletin and CVE records.

Product
Langflow OSS (IBM; open-source AI agent and workflow builder)
Versions
1.0.0 through 1.12.2 (fixed 1.12.3; 1.12.5 is the latest release at time of checking)
CVSS
Critical (CVE-2026-104334 and CVE-2026-93674, CVSS 3.1, IBM); most others 7.5 to 8.8
Exploited in Australia?
unknown
Patch to
Upgrade Langflow to 1.12.3 or later (latest 1.12.x preferred), including container images and desktop installs. Keep Langflow off the public internet or behind authenticated access, turn off auto-login and open sign-up, limit who can create or import flows, run it under a low-privilege account without access to cloud metadata or production secrets, and rotate API keys and stored credentials held in Langflow if an instance was exposed.

Primary: IBM — Security Bulletin: Langflow OSS is affected by multiple vulnerabilities (2 Oct 2026) · Vendor: CVE record — CVE-2026-104334 (IBM CNA, published 6 Oct 2026) · CVE: CVE-2026-104334, CVE-2026-93674, CVE-2026-97676, CVE-2026-97674, CVE-2026-97677, CVE-2026-103360, CVE-2026-97680, CVE-2026-101331, CVE-2026-93678, CVE-2026-93679 · PyPI — langflow releases (1.12.3 released 22 Sep 2026)

tech ai