Junglewise Threat Intelligence

CVE-2026-18729: IBM Langflow OSS code injection in code generation

CVE-2026-18729 · Severity: high · CVSS 8.8 · Published 2026-08-28

Technologies: IBM Langflow OSS, Langflow. Vendors: IBM, Langflow.

Executive brief

IBM Langflow is a platform for building and executing AI workflow applications. A remote authenticated attacker can execute arbitrary Python code and operating system commands on the server by exploiting improper validation of dynamically generated code, bypassing hardening policies designed to restrict custom code execution. This could allow an attacker with valid credentials to gain full control of the backend server and access sensitive data.

Technical details

The vulnerability is a code injection issue (CWE-94) in IBM Langflow OSS affecting versions 1.0.0–1.11.1. The root cause is improper control of code generation and insufficient enforcement of code-execution policies. A remote authenticated attacker can bypass the allow_custom_components=false hardening policy through multiple vectors: (1) the PythonFunction component lacks runtime code-execution gates, (2) the RunFlow component's private tweak channel filters only literal "code" field names and does not enforce blocking, and (3) the create_input_schema_from_dict function allows attacker-controlled flow template type fields to reach Pydantic's ForwardRef evaluation, which internally calls eval() with unrestricted builtins. Successful exploitation allows arbitrary Python and OS command execution within the server process context. IBM recommends upgrading to Langflow OSS version 1.11.2 or later.

Affected products

  • IBM Langflow OSS 1.0.0 through 1.11.1

Timeline

  • 2026-08-28: disclosed

References

Related threats