CVE Details

CVE-2026-9198 IBM Langflow Code Injection Vulnerability
Published: 2026-08-04 CVSS: 9.8 CRITICAL Product: IBM Langflow Due Date: 2026-08-07

Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.

GitHub PoC

Warning: GitHub PoC repositories are unverified. Some may be fake or contain malware. Use caution and review code before running anything.
  • killvxk/gitweekly • ⭐ 103 • 2025-07-22 • Conf: 95.0%
  • 收集各种有趣的github项目
  • 0xgh057r3c0n/CVE-2026-9198 • ⭐ 1 • 2026-07-24 • Conf: 95.0%
  • IBM Langflow Unauthenticated RCE via Auto-Login Bypass
  • ywh-jfellus/CVE-2026-9198 • ⭐ 0 • 2026-07-24 • Conf: 95.0%
  • Proof of Concept for CVE-2026-9198 - IBM Langflow Unauthenticated RCE via Auto-Login Bypass

FIRST EPSS

EPSS estimates the probability of exploitation in the next 30 days. Higher values indicate higher likelihood of real-world exploitation.

Timeline

CVE Stalker KEV MITRE GitHub FIRST (EPSS)

MITRE

CVSS

  • Score: 9.8
  • Severity: CRITICAL
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

SSVC

  • Exploitation: active
  • Automatable: yes
  • Technical Impact: total

References

Show Raw Data
Key Remaining Key Value
dataType CVE_RECORD
dataVersion 5.2
cveMetadata > cveId CVE-2026-9198
cveMetadata > assignerOrgId 9a959283-ebb5-44b6-b705-dcc2bbced522
cveMetadata > state PUBLISHED
cveMetadata > assignerShortName ibm
cveMetadata > dateReserved 2026-05-21T15:40:11.465Z
cveMetadata > datePublished 2026-07-17T17:36:11.246Z
cveMetadata > dateUpdated 2026-08-04T19:58:24.531Z
containers > cna > providerMetadata > orgId 9a959283-ebb5-44b6-b705-dcc2bbced522
containers > cna > providerMetadata > shortName ibm
containers > cna > providerMetadata > dateUpdated 2026-07-17T17:36:11.246Z
containers > cna > title Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
containers > cna > problemTypes > 0 > descriptions > 0 > lang en
containers > cna > problemTypes > 0 > descriptions > 0 > cweId CWE-94
containers > cna > problemTypes > 0 > descriptions > 0 > description CWE-94 Improper Control of Generation of Code ('Code Injection')
containers > cna > problemTypes > 0 > descriptions > 0 > type CWE
containers > cna > affected > 0 > vendor IBM
containers > cna > affected > 0 > product Langflow OSS
containers > cna > affected > 0 > versions > 0 > status affected
containers > cna > affected > 0 > versions > 0 > version 1.0.0
containers > cna > affected > 0 > versions > 0 > lessThanOrEqual 1.10.0
containers > cna > affected > 0 > versions > 0 > versionType semver
containers > cna > affected > 0 > cpes > 0 cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 1 cpe:2.3:a:ibm:langflow_oss:1.10.0:*:*:*:*:*:*:*
containers > cna > descriptions > 0 > lang en
containers > cna > descriptions > 0 > value IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments
containers > cna > descriptions > 0 > supportingMedia > 0 > type text/html
containers > cna > descriptions > 0 > supportingMedia > 0 > base64 False
containers > cna > descriptions > 0 > supportingMedia > 0 > value <p>IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments</p>
containers > cna > references > 0 > url https://www.ibm.com/support/pages/node/7278927
containers > cna > references > 0 > tags > 0 vendor-advisory
containers > cna > references > 0 > tags > 1 patch
containers > cna > metrics > 0 > format CVSS
containers > cna > metrics > 0 > scenarios > 0 > lang en
containers > cna > metrics > 0 > scenarios > 0 > value GENERAL
containers > cna > metrics > 0 > cvssV3_1 > version 3.1
containers > cna > metrics > 0 > cvssV3_1 > attackVector NETWORK
containers > cna > metrics > 0 > cvssV3_1 > attackComplexity LOW
containers > cna > metrics > 0 > cvssV3_1 > privilegesRequired NONE
containers > cna > metrics > 0 > cvssV3_1 > userInteraction NONE
containers > cna > metrics > 0 > cvssV3_1 > scope UNCHANGED
containers > cna > metrics > 0 > cvssV3_1 > confidentialityImpact HIGH
containers > cna > metrics > 0 > cvssV3_1 > integrityImpact HIGH
containers > cna > metrics > 0 > cvssV3_1 > availabilityImpact HIGH
containers > cna > metrics > 0 > cvssV3_1 > baseSeverity CRITICAL
containers > cna > metrics > 0 > cvssV3_1 > baseScore 9.8
containers > cna > metrics > 0 > cvssV3_1 > vectorString CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
containers > cna > solutions > 0 > lang en
containers > cna > solutions > 0 > value IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.10.1 https://pypi.org/project/langflow/
containers > cna > solutions > 0 > supportingMedia > 0 > type text/html
containers > cna > solutions > 0 > supportingMedia > 0 > base64 False
containers > cna > solutions > 0 > supportingMedia > 0 > value <p>IBM strongly recommends addressing the vulnerability now by upgrading <a href="https://pypi.org/project/langflow/" rel="nofollow">Langflow OSS to version 1.10.1</a></p>
containers > cna > x_generator > engine ibm-cvegen
containers > adp > 0 > metrics > 0 > other > type ssvc
containers > adp > 0 > metrics > 0 > other > content > id CVE-2026-9198
containers > adp > 0 > metrics > 0 > other > content > role CISA Coordinator
containers > adp > 0 > metrics > 0 > other > content > options > 0 > Exploitation active
containers > adp > 0 > metrics > 0 > other > content > options > 1 > Automatable yes
containers > adp > 0 > metrics > 0 > other > content > options > 2 > Technical Impact total
containers > adp > 0 > metrics > 0 > other > content > version 2.0.3
containers > adp > 0 > metrics > 0 > other > content > timestamp 2026-08-04T17:42:22.802585Z
containers > adp > 0 > metrics > 1 > other > type kev
containers > adp > 0 > metrics > 1 > other > content > dateAdded 2026-08-04
containers > adp > 0 > metrics > 1 > other > content > reference https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-9198
containers > adp > 0 > references > 0 > url https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-9198
containers > adp > 0 > references > 0 > tags > 0 government-resource
containers > adp > 0 > title CISA ADP Vulnrichment
containers > adp > 0 > providerMetadata > orgId 134c704f-9b21-4f2e-91b3-4a467353bcc0
containers > adp > 0 > providerMetadata > shortName CISA-ADP
containers > adp > 0 > providerMetadata > dateUpdated 2026-08-04T19:58:24.531Z
containers > adp > 0 > timeline > 0 > time 2026-08-04T00:00:00.000Z
containers > adp > 0 > timeline > 0 > lang en
containers > adp > 0 > timeline > 0 > value CVE-2026-9198 added to CISA KEV