


Perceptive Security
SOC/SIEM Consultancy

IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox implementation.
Published:
29 July 2026 at 22:00:00
Alert date:
30 July 2026 at 20:07:35
Source:
nvd.nist.gov
Enterprise Applications, Web Technologies, Zero-Day Vulnerabilities
IBM Langflow OSS versions 1.0.0 through 1.10.1 are affected by an improper input validation vulnerability located in the PythonREPL sandbox implementation. This flaw could potentially allow attackers to bypass sandbox restrictions and execute arbitrary code or perform unauthorized actions. The vulnerability is tracked as CVE-2026-13435 and is currently awaiting full analysis by NVD. IBM has published a support advisory regarding this issue. The affected product is an open-source AI workflow builder. Users of the affected versions are advised to consult IBM's support pages for remediation guidance. The current criticality is rated High, indicating significant risk to affected deployments.
Technical details
Mitigation steps:
Affected products:
IBM Langflow OSS 1.0.0 through 1.10.1
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
