9.8
CVE-2026-7803
- EPSS 0.42%
- Veröffentlicht 30.06.2026 19:15:45
- Zuletzt bearbeitet 02.07.2026 19:15:45
- CVE-Watchlists
- Unerledigt
Flow Validation Bypass via Empty Component Type Field
IBM Langflow OSS 1.0.0 through 1.10.0 could allow arbitrary code execution due to improper validation of flow nodes with missing or empty component type fields.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.42% | 0.34 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| IBM | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
https://www.ibm.com/support/pages/node/7278445