{"schema_version":1,"title":"IBM Langflow vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 96 vulnerabilities in IBM Langflow: 0 in the last 7 days and 91 in the last 90 days, 30 of them critical and 1 exploited in the wild. The most recent, CVE-2026-12944, was published on 14 September 2026.","url":"https://junglewise.ai/threats/technologies/langflow-oss","json_url":"https://junglewise.ai/threats/technologies/langflow-oss.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/langflow-oss","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":43,"all_time":96,"critical":30,"exploited":1,"last_7_days":0,"last_30_days":49,"last_90_days":91,"last_365_days":96},"latest":[{"cve":"CVE-2026-12944","cvss":9.6,"epss":0.0039,"slug":"cve-2026-12944-ibm-langflow-oss-arbitrary-code-execution-via-incomplete-import","title":"IBM Langflow OSS arbitrary code execution via incomplete import blocklist","severity":"critical","exploited":false,"published_at":"2026-09-14T22:16:56.95+00:00","url":"https://junglewise.ai/threats/cve-2026-12944-ibm-langflow-oss-arbitrary-code-execution-via-incomplete-import"},{"cve":"CVE-2026-12767","cvss":6.5,"epss":0.0022,"slug":"cve-2026-12767-ibm-langflow-oss-server-side-request-forgery-in-public-flow-build","title":"IBM Langflow OSS server-side request forgery in public flow build endpoint","severity":"medium","exploited":false,"published_at":"2026-09-14T21:17:00.847+00:00","url":"https://junglewise.ai/threats/cve-2026-12767-ibm-langflow-oss-server-side-request-forgery-in-public-flow-build"},{"cve":"CVE-2026-12766","cvss":5.4,"epss":0.0018,"slug":"cve-2026-12766-ibm-langflow-ssrf-in-multiple-components","title":"IBM Langflow SSRF in multiple components","severity":"medium","exploited":false,"published_at":"2026-09-14T21:17:00.713+00:00","url":"https://junglewise.ai/threats/cve-2026-12766-ibm-langflow-ssrf-in-multiple-components"},{"cve":"CVE-2026-12765","cvss":6.5,"epss":0.0022,"slug":"cve-2026-12765-ibm-langflow-oss-server-side-request-forgery-ssrf","title":"IBM Langflow OSS server-side request forgery (SSRF)","severity":"medium","exploited":false,"published_at":"2026-09-14T21:17:00.583+00:00","url":"https://junglewise.ai/threats/cve-2026-12765-ibm-langflow-oss-server-side-request-forgery-ssrf"},{"cve":"CVE-2026-12763","cvss":4.2,"epss":0.0015,"slug":"cve-2026-12763-ibm-langflow-oss-improper-cache-key-isolation-in-mcp-tools","title":"IBM Langflow OSS improper cache key isolation in MCP Tools","severity":"medium","exploited":false,"published_at":"2026-09-14T21:17:00.44+00:00","url":"https://junglewise.ai/threats/cve-2026-12763-ibm-langflow-oss-improper-cache-key-isolation-in-mcp-tools"},{"cve":"CVE-2026-17628","cvss":5.4,"epss":0.0034,"slug":"cve-2026-17628-ibm-langflow-improper-authentication-in-password-reset","title":"IBM Langflow improper authentication in password reset","severity":"medium","exploited":false,"published_at":"2026-09-14T20:16:42.14+00:00","url":"https://junglewise.ai/threats/cve-2026-17628-ibm-langflow-improper-authentication-in-password-reset"},{"cve":"CVE-2026-84889","cvss":8.8,"epss":0.0085,"slug":"cve-2026-84889-ibm-langflow-oss-path-traversal-arbitrary-file-write","title":"IBM Langflow OSS path traversal arbitrary file write","severity":"high","exploited":false,"published_at":"2026-09-10T22:17:04.347+00:00","url":"https://junglewise.ai/threats/cve-2026-84889-ibm-langflow-oss-path-traversal-arbitrary-file-write"},{"cve":"CVE-2026-81941","cvss":8.8,"epss":0.0063,"slug":"cve-2026-81941-ibm-langflow-oss-privilege-escalation-in-mcp-tools-component","title":"IBM Langflow OSS privilege escalation in MCP Tools component","severity":"high","exploited":false,"published_at":"2026-09-10T22:17:03.22+00:00","url":"https://junglewise.ai/threats/cve-2026-81941-ibm-langflow-oss-privilege-escalation-in-mcp-tools-component"},{"cve":"CVE-2026-81940","cvss":8.8,"epss":0.0081,"slug":"cve-2026-81940-ibm-langflow-oss-code-injection-in-flow-display-names","title":"IBM Langflow OSS code injection in flow display names","severity":"high","exploited":false,"published_at":"2026-09-10T22:17:03.083+00:00","url":"https://junglewise.ai/threats/cve-2026-81940-ibm-langflow-oss-code-injection-in-flow-display-names"},{"cve":"CVE-2026-81268","cvss":8.1,"epss":0.0043,"slug":"cve-2026-81268-ibm-langflow-oss-insufficient-api-key-session-expiration","title":"IBM Langflow OSS insufficient API key session expiration","severity":"high","exploited":false,"published_at":"2026-09-10T22:17:02.39+00:00","url":"https://junglewise.ai/threats/cve-2026-81268-ibm-langflow-oss-insufficient-api-key-session-expiration"},{"cve":"CVE-2026-81265","cvss":7.5,"epss":0.0039,"slug":"cve-2026-81265-ibm-langflow-oss-server-side-request-forgery-via-url-validation","title":"IBM Langflow OSS server-side request forgery via URL validation bypass","severity":"high","exploited":false,"published_at":"2026-09-10T22:17:02.253+00:00","url":"https://junglewise.ai/threats/cve-2026-81265-ibm-langflow-oss-server-side-request-forgery-via-url-validation"},{"cve":"CVE-2026-81213","cvss":8.6,"epss":0.0049,"slug":"cve-2026-81213-ibm-langflow-server-side-request-forgery-in-url-validation","title":"IBM Langflow server-side request forgery in URL validation","severity":"high","exploited":false,"published_at":"2026-09-10T22:17:02.11+00:00","url":"https://junglewise.ai/threats/cve-2026-81213-ibm-langflow-server-side-request-forgery-in-url-validation"},{"cve":"CVE-2026-81211","cvss":8.8,"epss":0.005,"slug":"cve-2026-81211-ibm-langflow-arbitrary-code-execution-in-custom-components","title":"IBM Langflow arbitrary code execution in custom components","severity":"high","exploited":false,"published_at":"2026-09-10T22:17:01.977+00:00","url":"https://junglewise.ai/threats/cve-2026-81211-ibm-langflow-arbitrary-code-execution-in-custom-components"},{"cve":"CVE-2026-81204","cvss":9.8,"epss":0.0086,"slug":"cve-2026-81204-ibm-langflow-oss-code-injection-in-graph-construction","title":"IBM Langflow OSS code injection in graph construction","severity":"critical","exploited":false,"published_at":"2026-09-10T22:17:01.58+00:00","url":"https://junglewise.ai/threats/cve-2026-81204-ibm-langflow-oss-code-injection-in-graph-construction"},{"cve":"CVE-2026-79742","cvss":8.8,"epss":0.0081,"slug":"cve-2026-79742-ibm-langflow-oss-arbitrary-code-execution-via-incomplete","title":"IBM Langflow OSS arbitrary code execution via incomplete environment variable blocklist","severity":"high","exploited":false,"published_at":"2026-09-10T22:17:00.78+00:00","url":"https://junglewise.ai/threats/cve-2026-79742-ibm-langflow-oss-arbitrary-code-execution-via-incomplete"},{"cve":"CVE-2026-79725","cvss":6.5,"epss":0.0042,"slug":"cve-2026-79725-ibm-langflow-oss-path-traversal-and-improper-access-control","title":"IBM Langflow OSS path traversal and improper access control","severity":"medium","exploited":false,"published_at":"2026-09-10T22:17:00.657+00:00","url":"https://junglewise.ai/threats/cve-2026-79725-ibm-langflow-oss-path-traversal-and-improper-access-control"},{"cve":"CVE-2026-79724","cvss":9.8,"epss":0.0067,"slug":"cve-2026-79724-ibm-langflow-os-command-injection-via-improper-neutralization","title":"IBM Langflow OS command injection via improper neutralization","severity":"critical","exploited":false,"published_at":"2026-09-10T22:17:00.53+00:00","url":"https://junglewise.ai/threats/cve-2026-79724-ibm-langflow-os-command-injection-via-improper-neutralization"},{"cve":"CVE-2026-79723","cvss":5,"epss":0.0035,"slug":"cve-2026-79723-ibm-langflow-oss-server-side-request-forgery-in-api-endpoint","title":"IBM Langflow OSS server-side request forgery in API endpoint validation","severity":"medium","exploited":false,"published_at":"2026-09-10T22:17:00.387+00:00","url":"https://junglewise.ai/threats/cve-2026-79723-ibm-langflow-oss-server-side-request-forgery-in-api-endpoint"},{"cve":"CVE-2026-78575","cvss":8.8,"epss":0.0079,"slug":"cve-2026-78575-ibm-langflow-oss-command-injection-in-mcp-stdio-configuration","title":"IBM Langflow OSS command injection in MCP stdio configuration","severity":"high","exploited":false,"published_at":"2026-09-10T22:17:00.13+00:00","url":"https://junglewise.ai/threats/cve-2026-78575-ibm-langflow-oss-command-injection-in-mcp-stdio-configuration"},{"cve":"CVE-2026-78571","cvss":8.8,"epss":0.0081,"slug":"cve-2026-78571-ibm-langflow-code-injection-in-eval-call","title":"IBM Langflow code injection in eval() call","severity":"high","exploited":false,"published_at":"2026-09-10T22:16:59.853+00:00","url":"https://junglewise.ai/threats/cve-2026-78571-ibm-langflow-code-injection-in-eval-call"},{"cve":"CVE-2026-78569","cvss":8.8,"epss":0.0065,"slug":"cve-2026-78569-ibm-langflow-oss-incomplete-denylist-code-execution","title":"IBM Langflow OSS incomplete denylist code execution","severity":"high","exploited":false,"published_at":"2026-09-10T22:16:59.723+00:00","url":"https://junglewise.ai/threats/cve-2026-78569-ibm-langflow-oss-incomplete-denylist-code-execution"},{"cve":"CVE-2026-76059","cvss":8.8,"epss":0.0068,"slug":"cve-2026-76059-ibm-langflow-oss-static-security-scanner-bypass-via-annotated","title":"IBM Langflow OSS static security scanner bypass via annotated class-body assignment","severity":"high","exploited":false,"published_at":"2026-09-10T22:16:59.59+00:00","url":"https://junglewise.ai/threats/cve-2026-76059-ibm-langflow-oss-static-security-scanner-bypass-via-annotated"},{"cve":"CVE-2026-9225","cvss":6.5,"epss":0.0035,"slug":"cve-2026-9225-ibm-langflow-access-control-bypass-in-file-read-component","title":"IBM Langflow access control bypass in File Read component","severity":"medium","exploited":false,"published_at":"2026-09-10T21:17:54.34+00:00","url":"https://junglewise.ai/threats/cve-2026-9225-ibm-langflow-access-control-bypass-in-file-read-component"},{"cve":"CVE-2026-85025","cvss":9.8,"epss":0.0061,"slug":"cve-2026-85025-ibm-langflow-arbitrary-code-execution-in-mcp-endpoints","title":"IBM Langflow arbitrary code execution in MCP endpoints","severity":"critical","exploited":false,"published_at":"2026-09-10T21:17:51.99+00:00","url":"https://junglewise.ai/threats/cve-2026-85025-ibm-langflow-arbitrary-code-execution-in-mcp-endpoints"},{"cve":"CVE-2026-17631","cvss":5,"epss":0.0023,"slug":"cve-2026-17631-ibm-langflow-oss-server-side-request-forgery-in-flow-components","title":"IBM Langflow OSS server-side request forgery in flow components","severity":"medium","exploited":false,"published_at":"2026-09-04T17:16:55.507+00:00","url":"https://junglewise.ai/threats/cve-2026-17631-ibm-langflow-oss-server-side-request-forgery-in-flow-components"}],"weekly":[{"week":"2026-06-29","critical":7,"exploited":0,"vulnerabilities":11},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":10,"exploited":1,"vulnerabilities":18},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":3,"exploited":0,"vulnerabilities":8},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-08-10","critical":1,"exploited":0,"vulnerabilities":1},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-24","critical":2,"exploited":0,"vulnerabilities":8},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":17},{"week":"2026-09-07","critical":3,"exploited":0,"vulnerabilities":18},{"week":"2026-09-14","critical":1,"exploited":0,"vulnerabilities":6},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"IBM AIX","slug":"aix","vulnerabilities":106,"url":"https://junglewise.ai/threats/technologies/aix"},{"name":"IBM PowerVM VIOS","slug":"powervm-vios","vulnerabilities":73,"url":"https://junglewise.ai/threats/technologies/powervm-vios"},{"name":"IBM i","slug":"i","vulnerabilities":67,"url":"https://junglewise.ai/threats/technologies/i"},{"name":"IBM WebSphere Application Server","slug":"websphere-application-server","vulnerabilities":54,"url":"https://junglewise.ai/threats/technologies/websphere-application-server"},{"name":"IBM WebSphere Application Server Liberty","slug":"websphere-application-server-liberty","vulnerabilities":34,"url":"https://junglewise.ai/threats/technologies/websphere-application-server-liberty"},{"name":"IBM Datastage On Cloud Pak For Data","slug":"datastage-on-cloud-pak-for-data","vulnerabilities":24,"url":"https://junglewise.ai/threats/technologies/datastage-on-cloud-pak-for-data"},{"name":"IBM Db2 Mirror For I","slug":"db2-mirror-for-i","vulnerabilities":22,"url":"https://junglewise.ai/threats/technologies/db2-mirror-for-i"},{"name":"IBM App Connect Enterprise","slug":"app-connect-enterprise","vulnerabilities":19,"url":"https://junglewise.ai/threats/technologies/app-connect-enterprise"},{"name":"IBM Db2","slug":"db2","vulnerabilities":19,"url":"https://junglewise.ai/threats/technologies/db2"},{"name":"IBM Mq","slug":"mq","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/mq"},{"name":"IBM Verify Identity Access","slug":"verify-identity-access","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/verify-identity-access"},{"name":"IBM Power Systems Firmware","slug":"power-systems-firmware","vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/power-systems-firmware"}],"technology":{"hub":true,"name":"IBM Langflow","slug":"langflow-oss","vendor":{"name":"IBM","slug":"ibm","url":"https://junglewise.ai/threats/vendors/ibm"},"aliases":[],"category":"library","homepage":"https://www.langflow.org/","repo_url":"https://github.com/langflow-ai/langflow","description":"Langflow is a low-code platform for building multi-agent and RAG applications.","url":"https://junglewise.ai/threats/technologies/langflow-oss"},"most_severe":[{"cve":"CVE-2026-9198","cvss":9.8,"epss":0.0189,"slug":"cve-2026-9198-ibm-langflow-oss-remote-code-execution-via-auto-login-bypass","title":"IBM Langflow OSS remote code execution via auto-login bypass","severity":"critical","exploited":true,"published_at":"2026-07-17T18:17:17.34+00:00","url":"https://junglewise.ai/threats/cve-2026-9198-ibm-langflow-oss-remote-code-execution-via-auto-login-bypass"},{"cve":"CVE-2026-10134","cvss":10,"slug":"cve-2026-10134-ibm-langflow-oss-unauthenticated-rce-in-pythoncodestructuredtool","title":"IBM Langflow OSS unauthenticated RCE in PythonCodeStructuredTool","severity":"critical","exploited":false,"published_at":"2026-06-30T20:17:26.883+00:00","url":"https://junglewise.ai/threats/cve-2026-10134-ibm-langflow-oss-unauthenticated-rce-in-pythoncodestructuredtool"},{"cve":"CVE-2026-10561","cvss":10,"slug":"cve-2026-10561-ibm-langflow-oss-remote-code-execution-in-pythonreplcomponent","title":"IBM Langflow OSS remote code execution in PythonREPLComponent","severity":"critical","exploited":false,"published_at":"2026-06-22T14:16:25.023+00:00","url":"https://junglewise.ai/threats/cve-2026-10561-ibm-langflow-oss-remote-code-execution-in-pythonreplcomponent"},{"cve":"CVE-2026-19295","cvss":9.9,"epss":0.0327,"slug":"cve-2026-19295-ibm-langflow-oss-eval-injection-in-schema-creation","title":"IBM Langflow OSS eval injection in schema creation","severity":"critical","exploited":false,"published_at":"2026-08-28T22:16:47.613+00:00","url":"https://junglewise.ai/threats/cve-2026-19295-ibm-langflow-oss-eval-injection-in-schema-creation"},{"cve":"CVE-2026-12946","cvss":9.9,"slug":"cve-2026-12946-ibm-langflow-oss-code-injection-in-cuga-codeagent","title":"IBM Langflow OSS code injection in CUGA CodeAgent","severity":"critical","exploited":false,"published_at":"2026-07-30T20:16:52.293+00:00","url":"https://junglewise.ai/threats/cve-2026-12946-ibm-langflow-oss-code-injection-in-cuga-codeagent"},{"cve":"CVE-2026-13435","cvss":9.9,"slug":"cve-2026-13435-ibm-langflow-oss-code-injection-in-pythonrepl-sandbox","title":"IBM Langflow OSS code injection in PythonREPL sandbox","severity":"critical","exploited":false,"published_at":"2026-07-30T19:17:06.84+00:00","url":"https://junglewise.ai/threats/cve-2026-13435-ibm-langflow-oss-code-injection-in-pythonrepl-sandbox"},{"cve":"CVE-2026-8859","cvss":9.9,"slug":"cve-2026-8859-ibm-langflow-oss-path-traversal-in-apirequest-component","title":"IBM Langflow OSS path traversal in APIRequest component","severity":"critical","exploited":false,"published_at":"2026-07-17T20:17:31.643+00:00","url":"https://junglewise.ai/threats/cve-2026-8859-ibm-langflow-oss-path-traversal-in-apirequest-component"},{"cve":"CVE-2026-8635","cvss":9.9,"slug":"cve-2026-8635-ibm-langflow-oss-privilege-escalation-in-python-interpreter","title":"IBM Langflow OSS privilege escalation in Python Interpreter component","severity":"critical","exploited":false,"published_at":"2026-07-17T20:17:31.527+00:00","url":"https://junglewise.ai/threats/cve-2026-8635-ibm-langflow-oss-privilege-escalation-in-python-interpreter"},{"cve":"CVE-2026-8481","cvss":9.9,"slug":"cve-2026-8481-ibm-langflow-oss-remote-code-execution-in-code-validation-endpoint","title":"IBM Langflow OSS remote code execution in code validation endpoint","severity":"critical","exploited":false,"published_at":"2026-07-17T20:17:30.747+00:00","url":"https://junglewise.ai/threats/cve-2026-8481-ibm-langflow-oss-remote-code-execution-in-code-validation-endpoint"},{"cve":"CVE-2026-8476","cvss":9.9,"slug":"cve-2026-8476-ibm-langflow-oss-remote-code-execution-in-asyncdiskcache","title":"IBM Langflow OSS remote code execution in AsyncDiskCache","severity":"critical","exploited":false,"published_at":"2026-07-17T20:17:30.623+00:00","url":"https://junglewise.ai/threats/cve-2026-8476-ibm-langflow-oss-remote-code-execution-in-asyncdiskcache"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}