CVE-2026-88962
- EPSS 0.79%
- Veröffentlicht 07.10.2026 00:02:53
- Zuletzt bearbeitet 08.10.2026 18:22:28
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper control of code generation.
CVE-2026-93443
- EPSS 0.58%
- Veröffentlicht 07.10.2026 00:02:36
- Zuletzt bearbeitet 08.10.2026 18:28:44
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in code.
CVE-2026-93448
- EPSS 0.64%
- Veröffentlicht 07.10.2026 00:02:18
- Zuletzt bearbeitet 09.10.2026 02:17:04
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.
CVE-2026-93449
- EPSS 0.58%
- Veröffentlicht 07.10.2026 00:02:05
- Zuletzt bearbeitet 08.10.2026 18:24:54
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper control of code generation.
CVE-2026-93445
- EPSS 0.61%
- Veröffentlicht 07.10.2026 00:01:50
- Zuletzt bearbeitet 08.10.2026 18:23:20
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper control of generation of code.
CVE-2026-93447
- EPSS 0.43%
- Veröffentlicht 07.10.2026 00:01:39
- Zuletzt bearbeitet 08.10.2026 18:24:12
IBM Langflow OSS 1.0.0 through 1.12.2 could allow an attacker with access to the server secret and Redis write access to submit a malicious serialized cache value. When the value was retrieved, deserialization could have executed attacker-controlled ...
CVE-2026-93675
- EPSS 0.68%
- Veröffentlicht 07.10.2026 00:01:27
- Zuletzt bearbeitet 08.10.2026 18:25:15
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to an expected dependency confusion.
CVE-2026-93677
- EPSS 0.46%
- Veröffentlicht 07.10.2026 00:01:14
- Zuletzt bearbeitet 08.10.2026 18:14:08
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to exposure of sensitive information to an unauthorized actor.
CVE-2026-93678
- EPSS 0.38%
- Veröffentlicht 07.10.2026 00:01:03
- Zuletzt bearbeitet 09.10.2026 02:17:04
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper authorization.
CVE-2026-93679
- EPSS 0.48%
- Veröffentlicht 07.10.2026 00:00:53
- Zuletzt bearbeitet 08.10.2026 01:25:42
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to cause a denial of service due to uncontrolled resource consumption during ZIP file extraction.