Junglewise Threat Intelligence

CVE-2026-12946: IBM Langflow OSS code injection in CUGA CodeAgent

CVE-2026-12946 · Severity: critical · CVSS 9.9 · Published 2026-07-30

Executive brief

IBM Langflow OSS, a tool used for building and deploying AI applications, contains a critical security flaw in its code execution component. An authorized user can bypass security protections to run unauthorized commands on the underlying server. This could lead to a complete system takeover, theft of sensitive data, or disruption of AI services.

Technical details

A code injection vulnerability (CWE-94) exists in the CUGA component's CodeAgent within IBM Langflow OSS. The flaw is located in the Python code execution path, where improper input validation allows for object graph introspection. An authenticated attacker can leverage this to recover restricted modules and bypass security validators, ultimately executing arbitrary commands within the server process. The vulnerability is reachable over the network with low privileges and has a high impact on confidentiality, integrity, and availability. Users should upgrade to version 1.10.1 to remediate the issue.

Affected products

  • IBM Langflow OSS 1.0.0 - 1.10.0

Timeline

  • 2026-07-02: advisory: Initial publication by IBM
  • 2026-07-30: disclosed: NVD publication date

References