Executive brief
IBM Langflow OSS, a tool used for building multi-agent AI applications, is vulnerable to a critical security flaw in its caching system. An attacker who can access the Redis database used by the application can execute malicious code with full system privileges. This could lead to a total compromise of the application, including the theft of sensitive AI secrets, customer data, and complete control over the underlying server.
Technical details
A deserialization vulnerability (CWE-502) exists in the Redis cache backend of IBM Langflow OSS versions 1.0.0 through 1.10.0. The application utilizes the 'dill.loads()' function to deserialize cached values retrieved from Redis without performing integrity verification. An attacker with network access to the Redis instance can inject malicious serialized payloads into the cache; these payloads are subsequently executed by application workers when the cached data is read. The issue is resolved in version 1.10.1 by implementing HMAC-SHA256 signature verification for all cached values to ensure only authorized payloads are processed.
Affected products
- IBM Langflow OSS 1.0.0 through 1.10.0
Timeline
- 2026-06-29: advisory: Initial publication by IBM
- 2026-06-30: disclosed: CVE published to NVD dataset