Junglewise Threat Intelligence

CVE-2026-9135: IBM Langflow OSS code injection in Policies component

CVE-2026-9135 · Severity: critical · CVSS 9.9 · Published 2026-07-17

Technologies: IBM Langflow OSS. Vendors: IBM.

Executive brief

IBM Langflow OSS, a tool used for building AI applications, contains a critical security flaw in its Policies component. An attacker with basic user access can bypass security restrictions to run malicious code on the server hosting the application. This could lead to a complete system takeover, theft of sensitive AI data, or the ability to modify other users' projects.

Technical details

A code injection vulnerability exists in IBM Langflow OSS versions 1.0.0 through 1.10.0 due to improper validation of dynamic CodeInput fields within the Policies component's ToolGuard integration. While the system validates the main component source code, it fails to check dynamic fields that store generated ToolGuard Python files. An authenticated attacker with flow creation privileges can persist malicious Python code in Flow.data, which is executed server-side when a guarded tool is invoked. This bypasses the 'allow_custom_components=false' security restriction. Furthermore, the vulnerability can be escalated to cross-tenant attacks using the 'update_flow_component_field' tool to inject code into other users' flows. The issue is fixed in version 1.10.1.

Affected products

  • IBM Langflow OSS 1.0.0 through 1.10.0

Timeline

  • 2026-07-02: advisory: Initial publication by IBM
  • 2026-07-17: disclosed: NVD publication date

References

Related threats