Executive brief
IBM Langflow is an open-source low-code platform for building AI applications and workflows. This vulnerability allows an unauthenticated remote attacker to inject and execute arbitrary code when constructing a workflow graph, potentially leading to full system compromise, data theft, and service disruption. An attacker could gain complete control over the server and access sensitive data including credentials and user information.
Technical details
CVE-2026-81204 is a code injection vulnerability in the graph construction component of IBM Langflow OSS versions 1.0.0 through 1.11.5. The vulnerability exists due to improper control of code generation when processing user-supplied graph data, allowing injection of arbitrary Python code. The attack requires no authentication and can be triggered via network access to the vulnerable endpoint. An attacker can achieve remote code execution with the privileges of the application process, leading to data exfiltration, system compromise, and potential lateral movement. IBM has classified this as critical with a CVSS v3.1 score of 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Patches or updates are available from IBM.
Affected products
- IBM Langflow OSS 1.0.0 through 1.11.5
Timeline
- 2026-09-10: disclosed