Junglewise Threat Intelligence

CVE-2026-79724: IBM Langflow OS command injection via improper neutralization

CVE-2026-79724 · Severity: critical · CVSS 9.8 · Published 2026-09-10

Technologies: IBM Langflow OSS, Langflow. Vendors: IBM, Langflow.

Executive brief

IBM Langflow is a low-code platform for building AI applications that allows developers to create and execute data pipelines and AI workflows. The application fails to properly validate and sanitize OS command inputs, allowing remote attackers to execute arbitrary commands on the server with full system privileges. Successful exploitation could lead to complete server compromise, theft of sensitive data and credentials, unauthorized file modifications, and lateral movement to other systems.

Technical details

The vulnerability stems from improper neutralization of special elements used in OS commands (CWE-78), combined with multiple incomplete code security controls and missing execution guards throughout the Langflow codebase. The attack vectors include: incomplete denylist in the agentic assistant code scanner that omits process-spawning primitives; logic errors in class-body assignment safety checks; unsanitized return-type annotation source passed directly to eval(); deprecated flow vertices endpoint accepting attacker-supplied flow data without owner-only validation; insufficient MCP stdio validation (particularly on Windows with alternate cmd.exe switches); missing OPENSSL_CONF environment variable blocklist allowing OpenSSL engine loading; and MCP Tools components bypassing all code-execution restrictions when invoked through flows. A remote unauthenticated attacker can achieve arbitrary OS command execution via multiple attack paths with no user interaction required. Patches addressing these issues are available from IBM.

Affected products

  • IBM Langflow OSS 1.0.0 through 1.11.5

Timeline

  • 2026-09-10: disclosed

References

Related threats