IBM has disclosed a critical code injection vulnerability (CVSS 9.8) in Langflow OSS versions 1.0.0 through 1.12.2. A remote attacker could exploit it to execute arbitrary code.
What Is It
CVE-2026-104334 comes from improper control of code generation in IBM Langflow OSS. This weakness is classified as CWE-94 (Code Injection). According to the NVD record, which IBM PSIRT ([email protected]) submitted, the flaw "could allow a remote attacker to execute arbitrary code."
The NVD record currently has a status of "Received." That means NVD has not yet completed its own analysis.
Why It Matters
IBM gave the vulnerability a CVSS v3.1 base score of 9.8 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. In plain terms:
- Attack Vector: Network. It can be exploited remotely.
- Attack Complexity: Low. No special conditions are needed.
- Privileges Required: None. No authentication is required.
- User Interaction: None. No action is needed from a victim.
- Impact: High impact on confidentiality, integrity, and availability.
The exploitability subscore is 3.9 and the impact subscore is 5.9. A flaw that needs no login and leads to arbitrary code execution is one of the most serious kinds of bug. A successful attack could give full control of the affected Langflow instance.
Exploitation status: The sources cited here do not say whether this CVE is being actively exploited or whether it is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Defenders should check the KEV catalog directly for current status.
What's Vulnerable
- Vendor: IBM
- Product: Langflow OSS
- Affected versions: 1.0.0 through 1.12.2, inclusive (semver)
The CPE identifiers listed in the record are:
cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*cpe:2.3:a:ibm:langflow_oss:1.12.2:*:*:*:*:*:*:*
Organizations running any Langflow OSS release in this range should treat it as affected.
Patch Status
The supplied NVD record does not name a fixed version or give specific remediation steps. IBM's security bulletin is referenced as the authoritative source for remediation guidance. Administrators should:
- Check the IBM support bulletin for fixed releases or mitigations.
- Find any Langflow OSS instances running versions 1.0.0–1.12.2, especially those reachable from the network.
- Apply vendor-supplied updates as soon as they are available.
Federal agencies and other organizations that track KEV deadlines should confirm in the CISA catalog whether a required-action date applies to this CVE.