Back

CRITICAL

Incomplete Security Scanner Blocklist Enables Network-Based Code Execution

Published Sep 14, 2026

Description

IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by submitting components containing socket or urllib imports. This enables: (1) AWS credential theft via IMDSv1 SSRF with full IAM role permissions, (2) arbitrary file exfiltration from the container filesystem, and (3) lateral movement to internal services (PostgreSQL, Redis) within the Docker network. The scanner incorrectly returns "validated": true, providing a false security signal.

Affected products

Remediation

Vendor solution

IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.10.1 https://pypi.org/project/langflow/

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner ibm
Published Sep 14, 2026
Updated Sep 16, 2026
Reserved Jun 22, 2026

CISA Vulnrichment

Updated Sep 15, 2026

NVD

Status Awaiting Analysis
Modified Sep 16, 2026

Red Hat

No data

ENISA EUVD

Assigner ibm
Published Sep 14, 2026
Updated Sep 16, 2026

GitHub

No data