Junglewise Threat Intelligence

CVE-2026-76059: IBM Langflow OSS static security scanner bypass via annotated class-body assignment

CVE-2026-76059 · Severity: high · CVSS 8.8 · Published 2026-09-10

Technologies: IBM Langflow OSS, Langflow. Vendors: IBM, Langflow.

Executive brief

IBM Langflow is an open-source platform that allows users to build and customize AI workflows by creating and deploying custom code components. An attacker with the ability to submit custom components can bypass the security scanner through a specially crafted code annotation, allowing them to execute arbitrary operating system commands with the privileges of the Langflow service, potentially leading to data theft, service disruption, or lateral movement within the organization's infrastructure.

Technical details

The vulnerability is a logic error in IBM Langflow's static security scanner used to validate custom component source code. An attacker can craft an annotated class-body assignment that resolves to a dangerous callable through alias tracking, but because the resolved value is never checked against the blocklist, the dangerous function passes validation. If the malicious component is deployed and executed, arbitrary OS commands execute on the server in-process with service privileges. This affects Langflow OSS versions 1.0.0 through 1.11.5; the attack requires the ability to submit custom components, which may be restricted to authenticated users depending on configuration.

Affected products

  • IBM Langflow OSS 1.0.0 through 1.11.5

Timeline

  • 2026-09-10: disclosed

References

Related threats