CVE-2026-101331
- EPSS 0.26%
- Veröffentlicht 06.10.2026 23:58:32
- Zuletzt bearbeitet 08.10.2026 18:16:35
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to insufficiently protected credentials.
CVE-2026-103360
- EPSS 0.47%
- Veröffentlicht 06.10.2026 23:58:15
- Zuletzt bearbeitet 08.10.2026 18:17:27
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.
CVE-2026-104334
- EPSS 0.62%
- Veröffentlicht 06.10.2026 23:57:57
- Zuletzt bearbeitet 08.10.2026 18:25:32
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper control of code generation.
CVE-2026-104335
- EPSS 0.57%
- Veröffentlicht 06.10.2026 23:57:43
- Zuletzt bearbeitet 09.10.2026 16:24:30
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper access control.
CVE-2026-105740
- EPSS 0.59%
- Veröffentlicht 05.10.2026 21:16:35
- Zuletzt bearbeitet 06.10.2026 19:17:41
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, any authenticated Langflow user can achieve Remote Code Execution (RCE) on the server by adding an MCP server with the "Stdio" transport. The user-supplied...
CVE-2026-76059
- EPSS 0.49%
- Veröffentlicht 10.09.2026 21:43:50
- Zuletzt bearbeitet 16.09.2026 00:49:27
IBM Langflow OSS 1.0.0 through 1.11.5 An attacker who could submit custom component source code could bypass the static security scanner by crafting an annotated class-body assignment that resolved to a dangerous callable through alias tracking; the ...
CVE-2026-78569
- EPSS 0.45%
- Veröffentlicht 10.09.2026 21:43:37
- Zuletzt bearbeitet 16.09.2026 00:49:50
IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to execute arbitrary code due to an incomplete denylist in the security scanner.
CVE-2026-78571
- EPSS 0.54%
- Veröffentlicht 10.09.2026 21:42:59
- Zuletzt bearbeitet 16.09.2026 00:49:58
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an unguarded eval() call on attacker-controlled input.
CVE-2026-78575
- EPSS 0.51%
- Veröffentlicht 10.09.2026 21:41:54
- Zuletzt bearbeitet 16.09.2026 00:50:33
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of command-line arguments in the MCP stdio server configuration.
- EPSS 0.24%
- Veröffentlicht 10.09.2026 21:41:37
- Zuletzt bearbeitet 16.09.2026 00:54:34
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of user-controlled API endpoints.