


Perceptive Security
SOC/SIEM Consultancy

IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input code.
Published:
29 July 2026 at 22:00:00
Alert date:
30 July 2026 at 21:05:50
Source:
nvd.nist.gov
Enterprise Applications, Emerging Technologies, Zero-Day Vulnerabilities
CVE-2026-12946 affects IBM Langflow OSS versions 1.0.0 through 1.10.0. The vulnerability allows a remote attacker to inject arbitrary code on the system due to improper control of user input code. This is classified as a code injection vulnerability, which typically carries high severity due to the potential for full system compromise. The flaw is remotely exploitable without physical access to the target system. IBM has published a support advisory addressing this issue. The NVD entry is currently awaiting full analysis and scoring. Organizations using affected versions of IBM Langflow OSS should review the IBM advisory and apply any available patches or mitigations promptly.
Technical details
Mitigation steps:
Affected products:
IBM Langflow OSS 1.0.0 through 1.10.0
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
