Skip to content
Multiple High-Risk Vulnerabilities in IBM Langflow OSS Disclosed

Multiple High-Risk Vulnerabilities in IBM Langflow OSS Disclosed

First seen 7 Oct 2026, 06:26 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 7, 2026 at 07:28 UTC
  • •IBM Langflow OSS has multiple high-risk vulnerabilities allowing remote code execution.
  • •CVE-2026-93443 and CVE-2026-93445 are critical for internet-accessible deployments.
  • •Immediate upgrades and access restrictions are recommended to mitigate risks.

IBM Langflow OSS versions 1.0.0 to 1.12.2 are affected by several vulnerabilities, including CVE-2026-93443 and CVE-2026-93445, which allow remote authenticated attackers to execute arbitrary code. CVE-2026-101331 and CVE-2026-103360 expose sensitive information due to insufficient protections. The vulnerabilities primarily affect self-hosted visual workflow and AI application platforms, especially those accessible over the internet. Attackers can exploit these flaws using low-privilege accounts without user interaction. The urgency for remediation is high, but specific exploitation indicators are not provided. Organizations are advised to upgrade to vendor-fixed releases and restrict network access. The vulnerabilities were disclosed on October 6 and 7, 2026, with CVSS scores ranging from 7.5 to 8.8, indicating significant risk.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-06
CVE-2026-103360 published
IBM disclosed a vulnerability that allows exposure of sensitive information due to improper pathname limitations.
Redpacketsecurity
2026-10-06
CVE-2026-101331 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-07
CVE-2026-93443 published
IBM disclosed a vulnerability allowing remote code execution due to improper neutralization of special elements.
Redpacketsecurity
2026-10-07
CVE-2026-93445 published
IBM disclosed a vulnerability that permits code execution through improper control of code generation.
Redpacketsecurity
2026-10-07
CVE-2026-88962 published
IBM disclosed a vulnerability allowing remote code execution due to improper control of code generation.
Redpacketsecurity

More articles in this cluster (6)

Following this threat?

Track CVE-2026-101331 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions of Langflow OSS are affected?
Versions 1.0.0 through 1.12.2 of IBM Langflow OSS are affected.
What is the risk level of these vulnerabilities?
The vulnerabilities have CVSS scores ranging from 7.5 to 8.8, indicating high risk.
What actions should organizations take?
Organizations should upgrade to the vendor-fixed releases and restrict network access to trusted users.