Cyber & AI intelligence
Wasteland.
Briefs indexed3048
Issues31
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-93674 2026-10-06

CVE-2026-93674: Critical Remote Code Execution in IBM Langflow OSS

"IBM Langflow OSS versions 1.0.0 through 1.12.2 contain a critical flaw (CVSS 9.8) that could let a remote, unauthenticated attacker execute arbitrary code."

IBM Langflow OSS versions 1.0.0 through 1.12.2 contain a critical flaw (CVSS 9.8) that could let a remote, unauthenticated attacker execute arbitrary code.

What Is It

CVE-2026-93674 is a remote code execution vulnerability in IBM Langflow OSS. IBM PSIRT says a remote attacker could use it to execute arbitrary code.

The published record describes the root cause in two different ways:

So the record does not settle whether the flaw is OS command injection or code injection. Both end in arbitrary code execution. IBM's security bulletin and NVD's analysis, once it is complete, should clarify the exact weakness.

The CVE has been published to NVD and currently has a status of "Received." NVD has not yet completed its own analysis.

Why It Matters

IBM gives the flaw a CVSS v3.1 base score of 9.8 (CRITICAL). The vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, which means:

The exploitability subscore is 3.9 and the impact subscore is 5.9. According to IBM's scoring, the flaw is easy to reach and could lead to full compromise of an affected system if exploited. NVD has not yet independently confirmed this assessment.

Exploitation status: No CISA Known Exploited Vulnerabilities (KEV) entry was found for this CVE. That means KEV does not confirm active exploitation at this time. The CVSS profile still makes it a high-priority fix.

What's Vulnerable

Vendor Product Affected Versions
IBM Langflow OSS 1.0.0 through 1.12.2 (inclusive)

The CPE entries in the record are cpe:2.3:a:ibm:langflow_oss:1.0.0 and cpe:2.3:a:ibm:langflow_oss:1.12.2. Any Langflow OSS deployment in that range should be treated as affected, especially if it can be reached over the network.

Patch Status

The NVD record does not name a fixed version. IBM has published a security bulletin, which should be checked for remediation guidance and updated releases. Because there is no KEV entry, CISA has not set a required action or due date.

Until you have reviewed the bulletin and applied the fix, organizations running Langflow OSS 1.0.0–1.12.2 should:

Sources