← Back to browse · API

CVE-2026-9198

Severity
HIGH
CVSS
8.0
EPSS
0.17053
Risk score
62.97
CISA KEV
Yes
PoC
Yes
Published
2026-08-07
Modified
2026-08-07
First seen
2026-08-05
Aliases
CNVD-2026-31205, EUVD-2026-45236, GHSA-5WM9-VGMG-CJV6
Products
IBM Langflow OSS >=1.0.0,<=1.10.0, IBM:Langflow, IBM:Langflow OSS 1.0.0 ≤1.10.0, langflow:langflow
Sources
nvd CVE-2026-9198
cisa.gov CVE-2026-9198
euvd EUVD-2026-45236
packetstorm 018512121999cde9f4aab01b|CVE-2026-9198
github 86736795b50f957ec747c0fa|CVE-2026-9198
cnvd CNVD-2026-31205

Description

IBM Langflow OSS is an open source low-code visual AI workflow construction tool from IBM in the United States. It allows developers to quickly build, deploy and iterate AI agents and RAG applications by dragging and dropping components. It also supports in-depth customization using Python to integrate enterprise systems. IBM Langflow OSS has a code injection vulnerability. This vulnerability is caused by flaws in the authentication and code execution modules. An attacker can use this vulnerability to achieve remote code execution by concatenating the /api/v1/auto_login and /api/v1/validate/code interfaces.

References