AI description
CVE-2026-8481 is a remote code execution vulnerability affecting IBM Langflow OSS versions 1.0.0 through 1.10.0. The flaw is located in the code validation API endpoint (`POST /api/v1/validate/code`), which is designed to validate Python code snippets used within visual AI workflows. Because the endpoint accepts user-supplied Python code and passes it directly to Python's built-in `exec()` function without sandboxing, input validation, or privilege restrictions, authenticated users can execute arbitrary system commands. An attacker can exploit this vulnerability by authenticating to the Langflow web interface or API and sending an HTTP POST request containing malicious Python code. Since the code runs within the context of the server process, successful exploitation allows the attacker to execute commands with the server's privileges, potentially enabling them to read sensitive data, install persistence, or pivot to connected AI model providers. A patch is available to address this issue.
- Description
- IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint. The POST /api/v1/validate/code endpoint accepts user-supplied Python code and executes it directly using Python's built-in exec() function without sandboxing, input validation, or privilege restrictions, enabling any authenticated user to execute arbitrary system commands with the full privileges of the Langflow server process.
- Source
- psirt@us.ibm.com
- NVD status
- Analyzed
- Products
- langflow
CVSS 3.1
- Type
- Secondary
- Base score
- 9.9
- Impact score
- 6
- Exploitability score
- 3.1
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
- psirt@us.ibm.com
- CWE-94
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
5
Default Langflow - auto_login mints you a SUPERUSER JWT. Then validate/code just exec()s your Python. CVE-2026-9198 = CVE-2026-9103 + CVE-2026-8481. IBM Langflow OSS 1.0.0-1.10.0 when AUTO_LOGIN is on (default pre-1.5). Chain: unauth GET /api/v1/auto_login —> SUPERUSER bea
@0xManan
10 Oct 2026
2505 Impressions
3 Retweets
31 Likes
10 Bookmarks
2 Replies
1 Quote
⚠️ Vulnerabilidades en productos IBM ❗ CVE-2026-9198 ❗ CVE-2026-9103 ❗ CVE-2026-8481 ➡️ Más info: https://t.co/HvNQ4gvgL8 https://t.co/R2JRwuxwAc
@CERTpy
29 Jul 2026
159 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*",
"matchCriteriaId": "A32785B1-3CF7-4BD0-B6F8-1AA77D4E565B",
"versionEndExcluding": "1.10.1",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*",
"matchCriteriaId": "387021A0-AF36-463C-A605-32EA7DAC172E",
"vulnerable": false
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*",
"matchCriteriaId": "703AF700-7A70-47E2-BC3A-7FD03B3CA9C1",
"vulnerable": false
},
{
"criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
"matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
}
]