CVE-2026-8481

Published Jul 17, 2026

Last updated 3 months ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-8481 is a remote code execution vulnerability affecting IBM Langflow OSS versions 1.0.0 through 1.10.0. The flaw is located in the code validation API endpoint (`POST /api/v1/validate/code`), which is designed to validate Python code snippets used within visual AI workflows. Because the endpoint accepts user-supplied Python code and passes it directly to Python's built-in `exec()` function without sandboxing, input validation, or privilege restrictions, authenticated users can execute arbitrary system commands. An attacker can exploit this vulnerability by authenticating to the Langflow web interface or API and sending an HTTP POST request containing malicious Python code. Since the code runs within the context of the server process, successful exploitation allows the attacker to execute commands with the server's privileges, potentially enabling them to read sensitive data, install persistence, or pivot to connected AI model providers. A patch is available to address this issue.

Description
IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint. The POST /api/v1/validate/code endpoint accepts user-supplied Python code and executes it directly using Python's built-in exec() function without sandboxing, input validation, or privilege restrictions, enabling any authenticated user to execute arbitrary system commands with the full privileges of the Langflow server process.
Source
psirt@us.ibm.com
NVD status
Analyzed
Products
langflow

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.9
Impact score
6
Exploitability score
3.1
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

psirt@us.ibm.com
CWE-94

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

5

Configurations

References

Sources include official advisories and independent security research.