CVE-2026-79724
- EPSS 0.47%
- Veröffentlicht 10.09.2026 21:41:21
- Zuletzt bearbeitet 16.09.2026 00:55:03
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.
CVE-2026-79725
- EPSS 0.3%
- Veröffentlicht 10.09.2026 21:40:06
- Zuletzt bearbeitet 16.09.2026 00:55:16
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to read arbitrary files due to improper access control.
CVE-2026-79742
- EPSS 0.54%
- Veröffentlicht 10.09.2026 21:39:44
- Zuletzt bearbeitet 16.09.2026 00:55:39
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an incomplete environment variable blocklist.
CVE-2026-81204
- EPSS 0.6%
- Veröffentlicht 10.09.2026 21:36:13
- Zuletzt bearbeitet 16.09.2026 00:55:47
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary code due to code injection during graph construction.
CVE-2026-81211
- EPSS 0.34%
- Veröffentlicht 10.09.2026 21:34:41
- Zuletzt bearbeitet 16.09.2026 00:56:12
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary Python code due to improper authorization of custom components in stored flows.
CVE-2026-81941
- EPSS 0.8%
- Veröffentlicht 10.09.2026 21:32:36
- Zuletzt bearbeitet 16.09.2026 00:59:19
IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute arbitrary operating system commands on the server at the privilege level of the application process by constructing a flow with an MCP Tools component...
CVE-2026-81213
- EPSS 0.36%
- Veröffentlicht 10.09.2026 21:32:00
- Zuletzt bearbeitet 16.09.2026 00:56:23
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to obtain sensitive information from internal network resources due to improper validation of user-supplied URLs.
CVE-2026-81265
- EPSS 0.23%
- Veröffentlicht 10.09.2026 21:31:41
- Zuletzt bearbeitet 16.09.2026 00:57:53
IBM Langflow OSS 1.0.0 through 1.11.5.
CVE-2026-81268
- EPSS 0.31%
- Veröffentlicht 10.09.2026 21:31:14
- Zuletzt bearbeitet 16.09.2026 00:58:26
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute flows and obtain sensitive information due to insufficient session expiration of API keys after user deactivation.
CVE-2026-81940
- EPSS 0.54%
- Veröffentlicht 10.09.2026 21:29:02
- Zuletzt bearbeitet 16.09.2026 00:58:41
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special characters in flow display names.