Back

CRITICAL

Arbitrary Code Execution in Python Interpreter Component

Published Jul 17, 2026

Description

IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute arbitrary system commands, and achieve full system compromise with Langflow service permissions.

Affected products

Remediation

Vendor solution

IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.10.1 https://pypi.org/project/langflow/

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ibm
Published Jul 17, 2026
Updated Jul 23, 2026
Reserved May 14, 2026
CISA Vulnrichment
Updated Jul 21, 2026
NVD
Status Analyzed
Modified Jul 23, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner ibm
Published Jul 17, 2026
Updated Jul 23, 2026
Exploited since n/a
EUVD-2026-45270