Technology · IBM
IBM Langflow vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 96 vulnerabilities in IBM Langflow: 0 in the last 7 days and 91 in the last 90 days, 30 of them critical and 1 exploited in the wild. The most recent, CVE-2026-12944, was published on 14 September 2026.
- Last 7 days
- 0
- Last 90 days
- 91
- Critical, all time
- 30
- Exploited in the wild
- 1
About IBM Langflow
Langflow is a low-code platform for building multi-agent and RAG applications.
Latest IBM Langflow vulnerabilities
- CVE-2026-12944: IBM Langflow OSS arbitrary code execution via incomplete import blocklistcriticalCVSS 9.6EPSS 0.4%
- CVE-2026-12767: IBM Langflow OSS server-side request forgery in public flow build endpointmediumCVSS 6.5EPSS 0.2%
- CVE-2026-12766: IBM Langflow SSRF in multiple componentsmediumCVSS 5.4EPSS 0.2%
- CVE-2026-12765: IBM Langflow OSS server-side request forgery (SSRF)mediumCVSS 6.5EPSS 0.2%
- CVE-2026-12763: IBM Langflow OSS improper cache key isolation in MCP ToolsmediumCVSS 4.2EPSS 0.1%
- CVE-2026-17628: IBM Langflow improper authentication in password resetmediumCVSS 5.4EPSS 0.3%
- CVE-2026-84889: IBM Langflow OSS path traversal arbitrary file writehighCVSS 8.8EPSS 0.9%
- CVE-2026-81941: IBM Langflow OSS privilege escalation in MCP Tools componenthighCVSS 8.8EPSS 0.6%
- CVE-2026-81940: IBM Langflow OSS code injection in flow display nameshighCVSS 8.8EPSS 0.8%
- CVE-2026-81268: IBM Langflow OSS insufficient API key session expirationhighCVSS 8.1EPSS 0.4%
- CVE-2026-81265: IBM Langflow OSS server-side request forgery via URL validation bypasshighCVSS 7.5EPSS 0.4%
- CVE-2026-81213: IBM Langflow server-side request forgery in URL validationhighCVSS 8.6EPSS 0.5%
- CVE-2026-81211: IBM Langflow arbitrary code execution in custom componentshighCVSS 8.8EPSS 0.5%
- CVE-2026-81204: IBM Langflow OSS code injection in graph constructioncriticalCVSS 9.8EPSS 0.9%
- CVE-2026-79742: IBM Langflow OSS arbitrary code execution via incomplete environment variable blocklisthighCVSS 8.8EPSS 0.8%
- CVE-2026-79725: IBM Langflow OSS path traversal and improper access controlmediumCVSS 6.5EPSS 0.4%
- CVE-2026-79724: IBM Langflow OS command injection via improper neutralizationcriticalCVSS 9.8EPSS 0.7%
- CVE-2026-79723: IBM Langflow OSS server-side request forgery in API endpoint validationmediumCVSS 5EPSS 0.4%
- CVE-2026-78575: IBM Langflow OSS command injection in MCP stdio configurationhighCVSS 8.8EPSS 0.8%
- CVE-2026-78571: IBM Langflow code injection in eval() callhighCVSS 8.8EPSS 0.8%
- CVE-2026-78569: IBM Langflow OSS incomplete denylist code executionhighCVSS 8.8EPSS 0.7%
- CVE-2026-76059: IBM Langflow OSS static security scanner bypass via annotated class-body assignmenthighCVSS 8.8EPSS 0.7%
- CVE-2026-9225: IBM Langflow access control bypass in File Read componentmediumCVSS 6.5EPSS 0.4%
- CVE-2026-85025: IBM Langflow arbitrary code execution in MCP endpointscriticalCVSS 9.8EPSS 0.6%
- CVE-2026-17631: IBM Langflow OSS server-side request forgery in flow componentsmediumCVSS 5EPSS 0.2%
Most severe IBM Langflow vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-9198: IBM Langflow OSS remote code execution via auto-login bypasscriticalexploited in the wildCVSS 9.8EPSS 1.9%
- CVE-2026-10134: IBM Langflow OSS unauthenticated RCE in PythonCodeStructuredToolcriticalCVSS 10
- CVE-2026-10561: IBM Langflow OSS remote code execution in PythonREPLComponentcriticalCVSS 10
- CVE-2026-19295: IBM Langflow OSS eval injection in schema creationcriticalCVSS 9.9EPSS 3.3%
- CVE-2026-12946: IBM Langflow OSS code injection in CUGA CodeAgentcriticalCVSS 9.9
- CVE-2026-13435: IBM Langflow OSS code injection in PythonREPL sandboxcriticalCVSS 9.9
- CVE-2026-8859: IBM Langflow OSS path traversal in APIRequest componentcriticalCVSS 9.9
- CVE-2026-8635: IBM Langflow OSS privilege escalation in Python Interpreter componentcriticalCVSS 9.9
- CVE-2026-8481: IBM Langflow OSS remote code execution in code validation endpointcriticalCVSS 9.9
- CVE-2026-8476: IBM Langflow OSS remote code execution in AsyncDiskCachecriticalCVSS 9.9
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 11 | 7 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 18 | 10 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 8 | 3 | |
| 3 Aug 2026 | 3 | 0 | |
| 10 Aug 2026 | 1 | 1 | |
| 17 Aug 2026 | 1 | 0 | |
| 24 Aug 2026 | 8 | 2 | |
| 31 Aug 2026 | 17 | 0 | |
| 7 Sep 2026 | 18 | 3 | |
| 14 Sep 2026 | 6 | 1 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/langflow-oss.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "IBM Langflow vulnerabilities", https://junglewise.ai/threats/technologies/langflow-oss, 26 September 2026.