IBM Langflow OSS versions 1.0.0 through 1.12.2 contain a critical flaw (CVSS 9.8) that could let a remote, unauthenticated attacker execute arbitrary code.
What Is It
CVE-2026-93674 is a remote code execution vulnerability in IBM Langflow OSS. IBM PSIRT says a remote attacker could use it to execute arbitrary code.
The published record describes the root cause in two different ways:
- The description says the product does not properly neutralize special elements used in an OS command. That wording usually describes OS command injection (CWE-78).
- The weakness field lists CWE-94 (Improper Control of Generation of Code, or "Code Injection").
So the record does not settle whether the flaw is OS command injection or code injection. Both end in arbitrary code execution. IBM's security bulletin and NVD's analysis, once it is complete, should clarify the exact weakness.
The CVE has been published to NVD and currently has a status of "Received." NVD has not yet completed its own analysis.
Why It Matters
IBM gives the flaw a CVSS v3.1 base score of 9.8 (CRITICAL). The vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, which means:
- Attack Vector: Network. It can be exploited remotely.
- Attack Complexity: Low. No special conditions are required.
- Privileges Required: None. No authentication is needed.
- User Interaction: None. No victim action is needed.
- Impact: High for confidentiality, integrity and availability.
The exploitability subscore is 3.9 and the impact subscore is 5.9. According to IBM's scoring, the flaw is easy to reach and could lead to full compromise of an affected system if exploited. NVD has not yet independently confirmed this assessment.
Exploitation status: No CISA Known Exploited Vulnerabilities (KEV) entry was found for this CVE. That means KEV does not confirm active exploitation at this time. The CVSS profile still makes it a high-priority fix.
What's Vulnerable
| Vendor | Product | Affected Versions |
|---|---|---|
| IBM | Langflow OSS | 1.0.0 through 1.12.2 (inclusive) |
The CPE entries in the record are cpe:2.3:a:ibm:langflow_oss:1.0.0 and cpe:2.3:a:ibm:langflow_oss:1.12.2. Any Langflow OSS deployment in that range should be treated as affected, especially if it can be reached over the network.
Patch Status
The NVD record does not name a fixed version. IBM has published a security bulletin, which should be checked for remediation guidance and updated releases. Because there is no KEV entry, CISA has not set a required action or due date.
Until you have reviewed the bulletin and applied the fix, organizations running Langflow OSS 1.0.0–1.12.2 should:
- find every instance they run
- limit network access to those instances
- follow IBM's guidance as soon as possible
Sources
- NVD, CVE-2026-93674
- IBM Security Bulletin (node 7290694)
- CISA Known Exploited Vulnerabilities Catalog (no entry for this CVE at time of writing)