← Back to browse · API

CVE-2026-10561

Severity
CRITICAL
CVSS
10.0
EPSS
0.00914
Risk score
40.32
CISA KEV
No
PoC
No
Published
2026-06-22
Modified
2026-06-23
First seen
2026-08-07
Aliases
EUVD-2026-38245, GHSA-FRVG-495W-M47V
Products
IBM:Langflow OSS 1.0.0 ≤1.9.3
Sources
euvd EUVD-2026-38245

Description

IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arbitrary code on the host system, resulting in complete compromise

References